← Back to CVE search

CVE-2026-78037

Xiiaozet LK100W

Description

Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary operating system commands with elevated privileges, potentially resulting in unauthorized access to sensitive information or complete device compromise.

CVSS 8.8EPSS 1.22%Risk 0.98
View source
Published
2026-08-28 00:18:16
Affected versions
unknown
Type
Other
Last modified
2026-08-28 16:18:26
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H