Impact
A flaw exists in the Configuration Data Handler of Technostrobe HI-LED-WR120-G2 firmware 5.5.0.1R6.03.30. An attacker can manipulate the argument passed to an unknown function that processes the /fs file, causing the device to leak sensitive configuration data. The vulnerability can be exploited remotely and publicly available exploits have already been released.
Affected Systems
The identified target is the Technostrobe HI-LED-WR120-G2 running firmware version 5.5.0.1R6.03.30. No additional firmware versions are listed as affected in the available data.
Risk and Exploitability
The CVSS score of 6.9 places the threat in the medium severity range. With no EPSS data and absence from the KEV catalog, the risk is primarily driven by the existence of a remote attack vector and an available exploit. If successful, the disclosure of configuration details compromises confidentiality and may enable further network or device compromise. The attack vector is inferred to be remote as the description states that the attack can be launched from outside the device.
OpenCVE Enrichment