Xiiaozet LK100W

Plan PatchCVSS 9.8ICS-CERT ICSA-26-239-01Aug 27, 2026
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

The Xiiaozet LK100W contains multiple critical vulnerabilities (CWE-78 OS command injection, CWE-306 missing authentication, CWE-288 authentication bypass) that allow remote attackers to take complete control of the device without credentials. Versions prior to 2.1.240 are vulnerable. Successful exploitation grants the attacker ability to execute arbitrary commands and modify device configuration and operation.

What this means
What could happen
An attacker with network access to the LK100W could gain full remote control of the device, allowing them to manipulate device settings, alter operational parameters, or disable normal function without authentication.
Who's at risk
Organizations operating Xiiaozet LK100W devices in water treatment, wastewater, power distribution, or other critical infrastructure monitoring and control applications should assess their exposure. This affects any facility using LK100W for SCADA functions, process automation, or remote monitoring.
How it could be exploited
An attacker sends a malicious network request to the LK100W without credentials. The device accepts and executes commands due to missing authentication checks and command injection flaws, giving the attacker complete control over device operations.
Prerequisites
  • Network access to the LK100W on its management or operational ports
  • No authentication required
Remotely exploitableNo authentication requiredLow complexity exploitationHigh CVSS (9.8)Affects control device with potential operational impact
Exploitability
Some exploitation risk — EPSS score 1.2%
Affected products (1)
ProductAffected VersionsFix Status
LK100W<2.1.240No fix yet
Remediation & Mitigation
0/3
Do now
0/1
HARDENINGRestrict network access to the LK100W to only authorized workstations and engineering systems using firewall rules
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpdate LK100W firmware to version 2.1.240 or later
Long-term hardening
0/1
HARDENINGPlace the LK100W on a segmented network separate from general IT systems and untrusted networks
API: /api/v1/advisories/0c62f082-7ccb-49d1-ab5c-2f486583f954

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.