Summary
CVE-2026-78239 is a critical missing authentication vulnerability (CWE-306) affecting the Xiiaozet LK100W device. The flaw allows a remote, unauthenticated attacker to invoke a critical management function, potentially enabling restricted administrative services and gaining unauthorized access to the device. The issue carries a CVSS v3.1 base score of 9.8 (Critical) and requires no user interaction or privileges to exploit.
Technical details
- Root cause: A critical management function on the Xiiaozet LK100W can be invoked without any authentication check, classified as CWE-306 (Missing Authentication for Critical Function).
- Trigger conditions: An attacker only needs network access to the device’s management interface; no credentials or prior access are required.
- Attack vector: Network (AV:N) — exploitable remotely over the network with low attack complexity and no privileges or user interaction needed.
- Impact: Successful exploitation can enable restricted/administrative services on the device, giving the attacker unauthorized administrative access and full impact to confidentiality, integrity, and availability of the device.
- This vulnerability was disclosed alongside two related flaws in the same product — an authenticated OS command injection issue (CVE-2026-78037) and an authentication bypass in an administrative service (CVE-2026-76943) — indicating broader authentication and input-handling weaknesses across the LK100W’s management interface.
Affected software
- Xiiaozet LK100W — all versions prior to 2.1.240
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade Xiiaozet LK100W devices to version 2.1.240 or later, as recommended by the vendor.
- If immediate patching is not possible:
- Restrict network access to the device’s management interface to trusted internal networks only; do not expose it directly to the internet.
- Place the device behind a firewall or VPN and limit access to authorized administrators.
- Monitor device logs and network traffic for unexpected administrative service activity or configuration changes.
- Apply general ICS/OT network segmentation best practices to limit exposure of management interfaces on internet-facing assets.

