LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-78037

Published
CVSS8.8
Severityhigh
WeaknessCWE-78
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary operating system commands with elevated privileges, potentially resulting in unauthorized access to sensitive information or complete device compromise.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-78037

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-78037.