Junglewise Threat Intelligence

CVE-2026-78037: Xiiaozet LK100W OS command injection in web management interface

CVE-2026-78037 · Severity: high · CVSS 8.8 · Published 2026-08-28

Technologies: Xiiaozet LK100W. Vendors: Xiiaozet.

Executive brief

The Xiiaozet LK100W is a network-connected industrial control device used in critical infrastructure environments worldwide. An authenticated attacker can inject arbitrary operating system commands through the web-based management interface and execute them with elevated privileges, potentially leading to complete device compromise and unauthorized access to sensitive information or systems.

Technical details

This vulnerability is an OS command injection flaw (CWE-78) in the web-based management interface of the LK100W. An authenticated attacker can inject and execute arbitrary operating system commands with elevated privileges by exploiting improper neutralization of special elements in command inputs. The attack requires network access to the management interface and valid authentication credentials. Successful exploitation allows full device compromise, including data exfiltration and system manipulation. Xiiaozet has released a patch in version 2.1.240 that addresses this and related vulnerabilities.

Affected products

  • Xiiaozet LK100W before 2.1.240

Timeline

  • 2026-08-27: disclosed
  • 2026-08-27: patched: Xiiaozet released version 2.1.240 as remediation

References

Related threats