Impact
The vulnerability resides in the index_config function of the /LoginCB file in Technostrobe HI‑LED‑WR120‑G2 firmware 5.5.0.1R6.03.30. Exploitation manipulates the authentication process, allowing an attacker to gain access without valid credentials. The result is unauthorized entry to the device’s control interface, potentially leading to control of device functions, data disclosure, and further lateral movement. The weakness is classified as improper authentication and corresponds to CWE‑287.
Affected Systems
Technostrobe’s HI‑LED‑WR120‑G2 network lighting controller, version 5.5.0.1R6.03.30. All units running this firmware are vulnerable; newer or patched builds are not explicitly cited as affected.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate to high severity. No EPSS value is available, and the vulnerability is not listed in CISA’s KEV catalog, but the exploit has been publicly disclosed and could be used remotely over an exposed network. Attackers can target the device from outside the local network, assuming the /LoginCB endpoint is reachable. In the absence of an official patch, the risk remains significant until mitigated or isolated.
OpenCVE Enrichment