CVE-2026-78037

EUVD-2026-67292
Xiiaozet LK100W is vulnerable to OS command injection through its 
web-based management interface. An authenticated attacker may be able to
 execute arbitrary operating system commands with elevated privileges, 
potentially resulting in unauthorized access to sensitive information or
 complete device compromise.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H