Description
A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Impacted is an unknown function of the file /Technostrobe/ of the component Endpoint. The manipulation results in improper access controls. The attack may be performed from remote. The exploit has been made public and could be used. Multiple endpoints are affected. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-04-05
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Immediate Patch
AI Analysis

Impact

A flaw in the Technostrobe HI-LED-WR120-G2 component allows remote manipulation of an unspecified function within the /Technostrobe/ endpoint. This improper access control can let attackers bypass restrictions and gain unauthorized access to device functionality or sensitive data. The public exploit demonstrates that the vulnerability can be leveraged without additional prerequisites, indicating a significant confidentiality and integrity risk.

Affected Systems

This issue affects Technostrobe HI‑LED‑WR120‑G2 devices running firmware version 5.5.0.1R6.03.30. Several endpoint interfaces on these units share the vulnerable functionality; any affected deployment is at risk.

Risk and Exploitability

The CVSS base score of 6.9 reflects a moderate to high impact. The EPSS score is unavailable, but public exploit code suggests the exploit is already being used. The vulnerability is not listed in the CISA KEV catalog. Attackers can target the device remotely using ordinary network access to the affected endpoint. Because the flaw involves improper access controls, no local privileges are required for exploitation.

Generated by OpenCVE AI on April 5, 2026 at 16:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Identify the firmware version currently installed on each device.
  • Download and apply the latest firmware update from Technostrobe that fixes the access control flaw.
  • If a patch is unavailable, restrict or disable remote management interfaces exposed to the Internet.
  • Implement network segmentation to isolate the device from critical infrastructure.
  • Monitor device logs for unauthorized access attempts and review for suspicious activity.

Generated by OpenCVE AI on April 5, 2026 at 16:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Apr 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Technostrobe hi-led-wr120-g2 Firmware
CPEs cpe:2.3:h:technostrobe:hi-led-wr120-g2:-:*:*:*:*:*:*:*
cpe:2.3:o:technostrobe:hi-led-wr120-g2_firmware:5.5.0.1r6.03.30:*:*:*:*:*:*:*
Vendors & Products Technostrobe hi-led-wr120-g2 Firmware

Tue, 07 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Technostrobe
Technostrobe hi-led-wr120-g2
Vendors & Products Technostrobe
Technostrobe hi-led-wr120-g2

Mon, 06 Apr 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 05 Apr 2026 14:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Impacted is an unknown function of the file /Technostrobe/ of the component Endpoint. The manipulation results in improper access controls. The attack may be performed from remote. The exploit has been made public and could be used. Multiple endpoints are affected. The vendor was contacted early about this disclosure but did not respond in any way.
Title Technostrobe HI-LED-WR120-G2 Endpoint access control
Weaknesses CWE-266
CWE-284
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:W/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:W/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:W/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Technostrobe Hi-led-wr120-g2 Hi-led-wr120-g2 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-06T16:18:11.013Z

Reserved: 2026-04-04T14:40:50.587Z

Link: CVE-2026-5569

cve-icon Vulnrichment

Updated: 2026-04-06T16:18:01.175Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-05T14:16:17.727

Modified: 2026-04-30T20:51:11.707

Link: CVE-2026-5569

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-06T21:56:42Z

Weaknesses