VORANT. Threat Intelligence Sign in Get the full feed

CISA flags flaws in Xiiaozet LK100W router

routine vulnerability technology

CISA warns of three vulnerabilities in Xiiaozet LK100W devices that could let attackers bypass authentication and execute arbitrary OS commands, leading to full device compromise.

CISA published an ICS advisory detailing three vulnerabilities affecting Xiiaozet LK100W devices running firmware versions below 2.1.240. The flaws include an OS command injection vulnerability (CVE-2026-78037) exploitable by an authenticated attacker via the web management interface, a missing authentication issue (CVE-2026-78239) that exposes a critical management function to unauthenticated remote attackers, and an authentication bypass flaw (CVE-2026-76943) in an administrative service that could allow attackers to obtain command execution capabilities. Successful exploitation of any of these vulnerabilities could result in unauthorized access to sensitive information or complete device compromise.

Xiiaozet, headquartered in China, has devices deployed worldwide within the Information Technology critical infrastructure sector. The vendor recommends users update to firmware version 2.1.240 to remediate all three issues. CISA notes no known public exploitation targeting these vulnerabilities has been reported at this time, and recommends standard ICS defensive measures including minimizing network exposure, isolating control system networks behind firewalls, and using secure remote access methods such as VPNs.

The vulnerabilities were responsibly disclosed to CISA by Byron Guernsey of Okachobi, LLC. Given the lack of confirmed in-the-wild exploitation and the availability of a vendor patch, this advisory represents a standard coordinated disclosure rather than an active threat, though the combination of authentication bypass and command injection flaws in an internet-facing management interface warrants prompt patching by affected organizations.

Mentioned in this report

Vulnerabilities CVE-2026-76943CVE-2026-78037CVE-2026-78239

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-01

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free