Critical firmware flaws expose Xiiaozet LK100W to remote takeover
Three high‑severity vulnerabilities—CVE‑2026‑78037, CVE‑2026‑78239 and CVE‑2026‑76943—have been identified in Xiiaozet LK100W firmware versions earlier than 2.1.240. The CISA advisory gives them a combined CVSS v3 base score of 9.8, which is as close to “critical” as you can get.
Why the bugs matter
CVE‑2026‑78239 lets an unauthenticated remote attacker invoke a privileged management function and flip on administrative services. In plain English: you could turn on the device’s “admin mode” without ever logging in.
CVE‑2026‑76943 is an authentication weakness that may let an attacker bypass access controls and run commands as if they were a local user. The advisory warns that successful exploitation could permit unauthorized access and potentially allow an attacker to take control of the device.
⚠️ The phrase “take control of the device” describes a potential impact and has not been observed in practice.
Who’s at risk
Any organization still running the vulnerable firmware—basically any deployment that hasn’t upgraded past 2.1.240—is in scope. The advisory notes no public exploitation has been reported so far, but the risk is high enough that remediation should be treated as urgent.
What to do now
- Upgrade every Xiiaozet LK100W to firmware version 2.1.240 or later immediately.
- If an upgrade isn’t possible right away, block inbound traffic to the device’s management ports at the network perimeter.
- Audit the device configuration for any enabled administrative services that weren’t deliberately turned on.
- Enforce strong, unique credentials for any remaining management interfaces; consider multi‑factor authentication where supported.
- Include the device in your regular vulnerability scanning and intrusion‑detection rulesets to catch any anomalous activity.
Background
The vulnerabilities were reported to CISA by Byron Guernsey of Okachobi, LLC, and the advisory was published on 2026‑08‑27. No threat actors have claimed credit, and CISA has not observed any public exploits to date.
