Cyber Resilience
← All news
Confirmed

Xiiaozet LK100W

Our takeCISA reports three vulnerabilities in Xiiaozet LK100W versions below 2.1.240 (CVSS 9.8) allow a remote attacker to take full control of the device. Update to 2.1.240 or later if you operate these — that includes small plants and shops running them without a security team.
Sources (1)
What this means for you — Security leader:CISA advisory: three vulnerabilities in Xiiaozet LK100W versions below 2.1.240 (CVSS 9.8) allow a remote attacker to take full control of the device. Update to 2.1.240 or later if you operate these.
What this means for you — Lean IT orgs:CISA reports these three vulnerabilities let a remote attacker take full control of the Xiiaozet LK100W. Update to version 2.1.240 or later if you use one.
What this means for you — MSP:Xiiaozet LK100W below 2.1.240 has three CVSS 9.8 flaws that let remote attackers take full device control. Check client OT/ICS inventories and update to 2.1.240 or later.
What this means for you — Researcher:CISA advisory: three vulnerabilities in Xiiaozet LK100W versions below 2.1.240 (CVSS 9.8) allow a remote attacker to take full control of the device. Update to 2.1.240 or later if you operate these.