CVE-2026-78037EPSS p78.6%
CVE-2026-78037CVE-2026-78037
Description
Xiiaozet LK100W is vulnerable to OS command injection through its
web-based management interface. An authenticated attacker may be able to
execute arbitrary operating system commands with elevated privileges,
potentially resulting in unauthorized access to sensitive information or
complete device compromise.
Scoring
| CVSS | 8.8 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 1.87% probability of exploitation · percentile 78.6% · 2026-10-05T12:00:23Z |
| Last modified | 2026-08-31 |