Government Advisory

Critical Security Flaws Found in Xiiaozet LK100W Devices

CISA · 27 Aug 2026
Key Takeaway If your business uses Xiiaozet LK100W devices, check the firmware version immediately and update to 2.1.240 or later as soon as a patch is available.

CISA has issued an advisory warning of three serious vulnerabilities affecting Xiiaozet LK100W devices running versions earlier than 2.1.240. The flaws include an OS command injection weakness, a missing authentication issue for a critical function, and an authentication bypass vulnerability that could allow attackers to gain access without proper credentials.

These vulnerabilities carry a high severity rating (CVSS v3 score of 9.8), meaning they are relatively easy to exploit and could give an attacker complete control of the device if successfully leveraged. The devices are deployed worldwide within the Information Technology sector, and the manufacturer, Xiiaozet, is headquartered in China.

While this advisory is primarily aimed at organisations using industrial or networked control devices, Australian small businesses that use any Xiiaozet LK100W equipment, or similar internet-connected devices from lesser-known vendors, should treat this as a priority to investigate. Unpatched devices with these kinds of flaws are attractive targets for automated scanning and exploitation by cybercriminals.

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.