CVE-2026-76943 PUBLISHED

Xiiaozet LK100W Authentication Bypass Using an Alternate Path or Channel

Assigner: icscert
Reserved: 25.08.2026 Published: 27.08.2026 Updated: 28.08.2026

Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. Successful exploitation could allow unauthorized interaction with privileged functionality and may lead to complete device compromise.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Xiiaozet
Product Xiiaozet LK100W
Versions Default: unaffected
  • affected from 0 to 2.1.240 (excl.)
  • Version 2.1.240 is unaffected

Solutions

Xiiaozet recommends users update to v2.1.240.

Credits

  • Byron Guernsey of Okachobi, LLC reported this vulnerability to CISA. finder

References

Problem Types

  • CWE-288 CWE