
THE Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory highlighting three critical vulnerabilities in the Xiiaozet LK100W device that could allow remote attackers to bypass authentication and execute arbitrary commands. The notice, referenced as ICSA-26-239-01, points to firmware releases prior to version 2.1.240 as affected. Users are urged to review the guidance and apply the recommended updates immediately. CISA advisory provides further details.
The flaws are tracked as CVE-2026-78239, CVE-2026-76943 and CVE-2026-78037, with the first and third receiving a CVSS v3 score of 9.8 and the middle one scored at 8.8. They comprise an OS command injection, a missing authentication check for a critical function and an authentication bypass that together enable unauthenticated remote code execution. Versions of the LK100W running firmware older than 2.1.240 are impacted, according to the vendor’s disclosure.
CISA notes that, despite the high severity, there have been no public reports of active exploitation or malware leveraging these weaknesses at the time of the advisory. The notice was released on 27 August 2026 and follows the standard process for industrial control systems where vendors are given a window to issue patches before details are made broader. No specific threat actors have been linked to the vulnerabilities in the available information.
Defenders should prioritise upgrading the LK100W to firmware version 2.1.240 or later, which addresses all three issues. Where immediate updating is not feasible, organisations are advised to limit network exposure by placing the devices behind firewalls, disabling unnecessary services and using virtual private networks for any remote access. Monitoring authentication logs and command execution events can help detect anomalous behaviour that might indicate an attempted breach.
In addition to patching, security teams should verify that asset inventories are up to date and that any legacy LK100W units are identified for replacement or isolation. Regular vulnerability scans and adherence to the principle of least privilege will reduce the attack surface. Following the advisory’s guidance on secure remote access and maintaining current firmware will help mitigate the risk posed by these flaws.