CVE-2026-78239

Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to enable administrative services that should be restricted. Successful exploitation may permit unauthorized access to the device.

  • Published Aug 28, 2026
  • CVSS 9.3 critical
  • 0.8% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-78239 at the National Vulnerability Database