Post
HIGH

CISA Warns of Critical Command Injection and Auth Bypass Flaws in Xiiaozet LK100W

· vulnerability · cve · privilege-escalation

CISA issued an advisory for the Xiiaozet LK100W (versions below 2.1.240), citing OS command injection, missing authentication for a critical function, and authentication bypass via an alternate path. The flaws carry a CVSS v3 score of 9.8.

Successful exploitation could let an attacker take full control of the device. The advisory lists the affected sector as Information Technology.