CVE-2026-78037
Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary operating system commands with elevated privileges, potentially resulting in unauthorized access to sensitive information or complete device compromise.
- Published Aug 28, 2026
- CVSS 8.7 high
- 1.9% chance of exploitation in the next 30 days (EPSS)