Junglewise Threat Intelligence

CVE-2026-76943: Xiiaozet LK100W authentication bypass in administrative service

CVE-2026-76943 · Severity: critical · CVSS 9.8 · Published 2026-08-28

Technologies: Xiiaozet LK100W. Vendors: Xiiaozet.

Executive brief

The Xiiaozet LK100W is an industrial control device deployed globally in critical infrastructure. A weakness in its administrative service allows attackers to bypass authentication and gain command execution capabilities, potentially leading to complete device compromise and unauthorized access to sensitive infrastructure.

Technical details

CVE-2026-76943 is an authentication bypass vulnerability (CWE-288) in the Xiiaozet LK100W administrative service that allows an attacker to circumvent intended access controls. The vulnerability is network-reachable and requires no prior authentication or user interaction. An attacker who successfully exploits this authentication bypass can obtain command execution capabilities and interact with privileged functionality, leading to complete device compromise. Xiiaozet recommends updating to version 2.1.240 or later.

Affected products

  • Xiiaozet LK100W <2.1.240

Timeline

  • 2026-08-27: disclosed
  • 2026-08-28: advisory

References

Related threats