← Browse

CVE-2026-78037

Medium

Elevated severity or exploit probability.

CVSS base
8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
1.9%
78.4th percentile
CISA KEV
Not listed
Weakness / dates
CWE-78
Published 2026-08-28 · modified 2026-08-31

Description

Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary operating system commands with elevated privileges, potentially resulting in unauthorized access to sensitive information or complete device compromise.

References

Official: NVD · CVE.org