# CISA flags flaws in Xiiaozet LK100W router

Published: 2026-08-27 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/f6887baa-240f-538a-a5ce-8c6940541b44/cisa-flags-flaws-in-xiiaozet-lk100w-router

> CISA warns of three vulnerabilities in Xiiaozet LK100W devices that could let attackers bypass authentication and execute arbitrary OS commands, leading to full device compromise.

CISA published an ICS advisory detailing three vulnerabilities affecting Xiiaozet LK100W devices running firmware versions below 2.1.240. The flaws include an OS command injection vulnerability (CVE-2026-78037) exploitable by an authenticated attacker via the web management interface, a missing authentication issue (CVE-2026-78239) that exposes a critical management function to unauthenticated remote attackers, and an authentication bypass flaw (CVE-2026-76943) in an administrative service that could allow attackers to obtain command execution capabilities. Successful exploitation of any of these vulnerabilities could result in unauthorized access to sensitive information or complete device compromise.

Xiiaozet, headquartered in China, has devices deployed worldwide within the Information Technology critical infrastructure sector. The vendor recommends users update to firmware version 2.1.240 to remediate all three issues. CISA notes no known public exploitation targeting these vulnerabilities has been reported at this time, and recommends standard ICS defensive measures including minimizing network exposure, isolating control system networks behind firewalls, and using secure remote access methods such as VPNs.

The vulnerabilities were responsibly disclosed to CISA by Byron Guernsey of Okachobi, LLC. Given the lack of confirmed in-the-wild exploitation and the availability of a vendor patch, this advisory represents a standard coordinated disclosure rather than an active threat, though the combination of authentication bypass and command injection flaws in an internet-facing management interface warrants prompt patching by affected organizations.

## Mentioned in this report

- Vulnerabilities: CVE-2026-76943, CVE-2026-78037, CVE-2026-78239

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-01

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/f6887baa-240f-538a-a5ce-8c6940541b44/cisa-flags-flaws-in-xiiaozet-lk100w-router.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
