HIGH
CISA Warns of Critical Command Injection and Auth Bypass Flaws in Xiiaozet LK100W
CISA issued an advisory for the Xiiaozet LK100W (versions below 2.1.240), citing OS command injection, missing authentication for a critical function, and authentication bypass via an alternate path. The flaws carry a CVSS v3 score of 9.8.
Successful exploitation could let an attacker take full control of the device. The advisory lists the affected sector as Information Technology.