Impact
A flaw in the Technostrobe HI-LED-WR120-G2 component allows remote manipulation of an unspecified function within the /Technostrobe/ endpoint. This improper access control can let attackers bypass restrictions and gain unauthorized access to device functionality or sensitive data. The public exploit demonstrates that the vulnerability can be leveraged without additional prerequisites, indicating a significant confidentiality and integrity risk.
Affected Systems
This issue affects Technostrobe HI‑LED‑WR120‑G2 devices running firmware version 5.5.0.1R6.03.30. Several endpoint interfaces on these units share the vulnerable functionality; any affected deployment is at risk.
Risk and Exploitability
The CVSS base score of 6.9 reflects a moderate to high impact. The EPSS score is unavailable, but public exploit code suggests the exploit is already being used. The vulnerability is not listed in the CISA KEV catalog. Attackers can target the device remotely using ordinary network access to the affected endpoint. Because the flaw involves improper access controls, no local privileges are required for exploitation.
OpenCVE Enrichment