web-based management interface. An authenticated attacker may be able to
execute arbitrary operating system commands with elevated privileges,
potentially resulting in unauthorized access to sensitive information or
complete device compromise.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Xiiaozet recommends users update to v2.1.240.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 28 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xiiaozet
Xiiaozet xiiaozet Lk100w |
|
| Vendors & Products |
Xiiaozet
Xiiaozet xiiaozet Lk100w |
Fri, 28 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary operating system commands with elevated privileges, potentially resulting in unauthorized access to sensitive information or complete device compromise. | |
| Title | Xiiaozet LK100W OS Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-08-28T14:13:51.266Z
Reserved: 2026-08-25T15:37:54.537Z
Link: CVE-2026-78037
Updated: 2026-08-28T14:04:37.977Z
Status : Received
Published: 2026-08-28T00:18:16.063
Modified: 2026-08-28T16:18:26.823
Link: CVE-2026-78037
No data.
OpenCVE Enrichment
Updated: 2026-08-28T16:13:24Z