CVE-2026-78037

Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary operating system commands with elevated privileges, potentially resulting in unauthorized access to sensitive information or complete device compromise.

  • Published Aug 28, 2026
  • CVSS 8.7 high
  • 1.9% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-78037 at the National Vulnerability Database