Critical Security Flaws Found in Xiiaozet LK100W Devices
CISA has issued an advisory warning of three serious vulnerabilities affecting Xiiaozet LK100W devices running versions earlier than 2.1.240. The flaws include an OS command injection weakness, a missing authentication issue for a critical function, and an authentication bypass vulnerability that could allow attackers to gain access without proper credentials.
These vulnerabilities carry a high severity rating (CVSS v3 score of 9.8), meaning they are relatively easy to exploit and could give an attacker complete control of the device if successfully leveraged. The devices are deployed worldwide within the Information Technology sector, and the manufacturer, Xiiaozet, is headquartered in China.
While this advisory is primarily aimed at organisations using industrial or networked control devices, Australian small businesses that use any Xiiaozet LK100W equipment, or similar internet-connected devices from lesser-known vendors, should treat this as a priority to investigate. Unpatched devices with these kinds of flaws are attractive targets for automated scanning and exploitation by cybercriminals.