


Perceptive Security
SOC/SIEM Consultancy

Xiiaozet LK100W is vulnerable to OS command injection through its
web-based management interface. An authenticated attacker may be able to
execute arbitrary o…
Published:
28 augustus 2026 om 00:00:00
Alert date:
28 augustus 2026 om 03:09:12
Source:
nvd.nist.gov
Mobile & IoT, Critical Infrastructure, Network Infrastructure
CVE-2026-78037 describes an OS command injection vulnerability affecting the Xiiaozet LK100W device through its web-based management interface. An authenticated attacker can exploit this flaw to execute arbitrary operating system commands with elevated privileges. Successful exploitation may lead to unauthorized access to sensitive information or complete device compromise. The vulnerability requires authentication, limiting the attack surface but not eliminating the risk from insider threats or compromised credentials. The issue has been reported via NVD and is accompanied by a CISA ICS advisory (ICSA-26-239-01), indicating relevance to operational technology and industrial control system environments. The CSAF advisory file is also available through CISA's GitHub repository.
Technical details
Mitigation steps:
Affected products:
Xiiaozet LK100W
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-78037
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-239-01.json
https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-01
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
