CVE-2026-78239
Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to enable administrative services that should be restricted. Successful exploitation may permit unauthorized access to the device.
- Published Aug 28, 2026
- CVSS 9.3 critical
- 0.8% chance of exploitation in the next 30 days (EPSS)