Executive brief
The Xiiaozet LK100W is an industrial control device deployed globally in critical infrastructure. A weakness in its administrative service allows attackers to bypass authentication and gain command execution capabilities, potentially leading to complete device compromise and unauthorized access to sensitive infrastructure.
Technical details
CVE-2026-76943 is an authentication bypass vulnerability (CWE-288) in the Xiiaozet LK100W administrative service that allows an attacker to circumvent intended access controls. The vulnerability is network-reachable and requires no prior authentication or user interaction. An attacker who successfully exploits this authentication bypass can obtain command execution capabilities and interact with privileged functionality, leading to complete device compromise. Xiiaozet recommends updating to version 2.1.240 or later.
Affected products
- Xiiaozet LK100W <2.1.240
Timeline
- 2026-08-27: disclosed
- 2026-08-28: advisory