Sceawere

Vulnerability Detail

CVE-2026-76943UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Xiiaozet LK100Wt Authentication Bypass

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
2h ago
Vendor
Xiiaozet
Product
Xiiaozet LK100W
Attack Type
CWE-288
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. Successful exploitation could allow unauthorized interaction with privileged functionality and may lead to complete device compromise.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-28T00:18:15.343Z",
  "pubdate": "2026-08-28T00:18:15.343Z",
  "executiveSummary": "The Xiiaozet LK100Wt device is susceptible to a critical authentication weakness within its administrative service interface.\nThis vulnerability allows an unauthenticated attacker to circumvent established access controls, effectively bypassing the security boundary intended to protect administrative functions.\nBy leveraging this flaw, an unauthorized actor can achieve arbitrary command execution, leading to a complete compromise of the device's operational integrity.\nThe vulnerability represents a severe security risk, as it permits full administrative control over the affected hardware, potentially exposing sensitive system configuration, data, or allowing the device to be used as a pivot point in a broader network attack.\nNo specific preconditions beyond network reachability of the administrative service are required to facilitate exploitation, making this a high-impact vulnerability that necessitates immediate attention.",
  "technicalDetails": "The vulnerability originates from an insecure implementation of the authentication mechanism within the Xiiaozet LK100Wt administrative service. The root cause is a failure to properly enforce session validation or credentials verification before permitting access to privileged system functions.\nIn a typical attack flow, the attacker identifies the administrative service, which is generally exposed over the network. By crafting a specific set of requests or utilizing non-standard parameters that the underlying service fails to sanitize or validate, the attacker triggers an authentication bypass. Because the service incorrectly assumes the legitimacy of the request, it grants the attacker entry into the administrative context without requiring valid credentials.\nOnce the authentication boundary is bypassed, the attacker gains access to internal API endpoints or administrative command-line interfaces exposed by the service. These interfaces often allow for the execution of system commands with elevated privileges, typically root or equivalent system-level permissions. The exploitation process involves sending specially crafted network packets or HTTP-based payloads to the vulnerable component, which the device then processes as legitimate administrative instructions.\nThe impact of successful exploitation is total device compromise. With the ability to execute arbitrary commands, an attacker can modify system configurations, install persistent backdoors, extract stored credentials, disable security auditing, or use the device as a persistent presence in the target environment. Furthermore, because the vulnerability resides in the core administrative service, it effectively renders standard authentication controls moot, providing an adversary with full control over the target's operating system environment. The attack does not require prior knowledge of the target's credentials, relying instead on the inherent flaw in how the administrative service manages session state and access control lists."
}
CVE-2026-76943: Xiiaozet LK100Wt Authentication Bypass (CRITICAL Severity, CVSS: 9.8) - Sceawere