Cyber Resilience
← All news
Confirmed

Xiiaozet LK100W

Our takeCISA advisory: three vulnerabilities in Xiiaozet LK100W versions below 2.1.240 (CVSS 9.8) allow a remote attacker to take full control of the device. Update to 2.1.240 or later if you operate these — that includes small plants and shops running them without a security team.
Sources (1)
What this means for you — Security leader:CISA reports active exploitation of three vulnerabilities in Xiiaozet LK100W <2.1.240 (CVSS 9.8) that let remote attackers take full control of the device. Update to 2.1.240 or later immediately if you operate these units.
What this means for you — Lean IT orgs:If you use a Xiiaozet LK100W device, update it to version 2.1.240 or newer right away. An attacker who reaches it can take complete control.
What this means for you — MSP:CISA reports active exploitation in Xiiaozet LK100W <2.1.240. Check every client that operates these devices and update to 2.1.240 or later; remote code execution gives full device control.
What this means for you — Researcher:CISA reports active exploitation of CVE-2026-78037, CVE-2026-78239 and CVE-2026-76943 in Xiiaozet LK100W <2.1.240 (CVSS 9.8). Successful exploitation grants full device control.