Xiiaozet LK100W exposes a critical management function that can be
invoked without authentication, allowing a remote attacker to enable
administrative services that should be restricted. Successful
exploitation may permit unauthorized access to the device.
invoked without authentication, allowing a remote attacker to enable
administrative services that should be restricted. Successful
exploitation may permit unauthorized access to the device.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Xiiaozet recommends users update to v2.1.240.
Workaround
No workaround given by the vendor.
References
History
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to enable administrative services that should be restricted. Successful exploitation may permit unauthorized access to the device. | |
| Title | Xiiaozet LK100W Missing Authentication for Critical Function | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-08-27T21:48:30.879Z
Reserved: 2026-08-25T15:37:54.548Z
Link: CVE-2026-78239
No data.
Status : Received
Published: 2026-08-28T00:18:16.197
Modified: 2026-08-28T00:18:16.197
Link: CVE-2026-78239
No data.
OpenCVE Enrichment
No data.
Weaknesses