CyberICT

CVE-2026-78037

Unspecified · Published August 28, 2026

CVSS v3.1

HIGH

Description

Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary operating system commands with elevated privileges, potentially resulting in unauthorized access to sensitive information or complete device compromise.

Affected Products

    CVSS Vector

    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H