administrative service that may allow an attacker to bypass intended
access controls and obtain command execution capabilities. Successful
exploitation could allow unauthorized interaction with privileged
functionality and may lead to complete device compromise.
No advisories yet.
Solution
Xiiaozet recommends users update to v2.1.240.
Workaround
No workaround given by the vendor.
Fri, 28 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xiiaozet
Xiiaozet xiiaozet Lk100w |
|
| Vendors & Products |
Xiiaozet
Xiiaozet xiiaozet Lk100w |
Fri, 28 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. Successful exploitation could allow unauthorized interaction with privileged functionality and may lead to complete device compromise. | |
| Title | Xiiaozet LK100W Authentication Bypass Using an Alternate Path or Channel | |
| Weaknesses | CWE-288 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-08-28T14:13:50.949Z
Reserved: 2026-08-25T15:37:54.554Z
Link: CVE-2026-76943
Updated: 2026-08-28T14:04:23.561Z
Status : Received
Published: 2026-08-28T00:18:15.343
Modified: 2026-08-28T16:18:26.203
Link: CVE-2026-76943
No data.
OpenCVE Enrichment
Updated: 2026-08-28T16:13:21Z