CVE-2026-78239

EUVD-2026-67293
Xiiaozet LK100W exposes a critical management function that can be 
invoked without authentication, allowing a remote attacker to enable 
administrative services that should be restricted. Successful 
exploitation may permit unauthorized access to the device.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H