Junglewise Threat Intelligence

CVE-2026-78239: Xiiaozet LK100W missing authentication in critical management function

CVE-2026-78239 · Severity: critical · CVSS 9.8 · Published 2026-08-28

Technologies: Xiiaozet LK100W. Vendors: Xiiaozet.

Executive brief

The Xiiaozet LK100W is an industrial control system device used in critical infrastructure environments worldwide. This vulnerability allows a remote attacker to invoke a critical management function without any authentication, enabling them to activate restricted administrative services and gain unauthorized access to the device. Successful exploitation could lead to complete device compromise and loss of control over connected infrastructure.

Technical details

The vulnerability is a missing authentication flaw (CWE-306) in the LK100W's web-based management interface that exposes a critical administrative function. An unauthenticated remote attacker can directly invoke this function over the network without providing credentials, allowing them to enable administrative services that should be access-restricted. This leads to unauthorized device access and can be chained with other vulnerabilities (CVE-2026-78037, CVE-2026-76943) to achieve complete system compromise. The flaw affects all versions before 2.1.240, and Xiiaozet has released a patched version addressing this issue.

Affected products

  • Xiiaozet LK100W <2.1.240

Timeline

  • 2026-08-27: disclosed
  • 2026-08-28: advisory

References

Related threats