Description
A weakness has been identified in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. This impacts an unknown function of the file /fs. Executing a manipulation of the argument cwd can lead to unrestricted upload. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-04-05
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A flaw was found in the Technostrobe HI‑LED‑WR120‑G2 firmware 5.5.0.1R6.03.30. By manipulating the "cwd" argument to the file /fs, an attacker can upload arbitrary files without restriction. Because the upload endpoint is reachable externally, the vulnerability can be triggered remotely, potentially allowing the placement of malicious code on the device and leading to remote code execution or other privilege‑escalating actions. The weakness corresponds to improper access control and unrestricted file upload.

Affected Systems

Technostrobe HI‑LED‑WR120‑G2 devices running firmware 5.5.0.1R6.03.30 are affected. No other product or version information is available from the CNA data.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate to high severity, and the exploit is publicly available. The EPSS score is not provided, but the lack of a KEV listing does not diminish the potential risk. Attackers can reach the vulnerable endpoint from the internet and can upload files that may be executed or used to compromise the device. The remote nature of the attack path and the possibility to upload dangerous files elevate the threat level for any deployed HI‑LED‑WR120‑G2 units.

Generated by OpenCVE AI on April 5, 2026 at 18:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply an updated firmware package that removes the unrestricted upload flaw.
  • If a firmware upgrade cannot be applied immediately, block external traffic to the /fs endpoint using a firewall or local network rules.
  • Implement network segmentation so that only trusted management networks can reach the device’s web interface.
  • Monitor log files for anomalous upload activity and enforce strict file type checks if possible.

Generated by OpenCVE AI on April 5, 2026 at 18:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Apr 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Technostrobe hi-led-wr120-g2 Firmware
CPEs cpe:2.3:h:technostrobe:hi-led-wr120-g2:-:*:*:*:*:*:*:*
cpe:2.3:o:technostrobe:hi-led-wr120-g2_firmware:5.5.0.1r6.03.30:*:*:*:*:*:*:*
Vendors & Products Technostrobe hi-led-wr120-g2 Firmware

Tue, 07 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Technostrobe
Technostrobe hi-led-wr120-g2
Vendors & Products Technostrobe
Technostrobe hi-led-wr120-g2

Mon, 06 Apr 2026 20:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 05 Apr 2026 15:45:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. This impacts an unknown function of the file /fs. Executing a manipulation of the argument cwd can lead to unrestricted upload. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title Technostrobe HI-LED-WR120-G2 fs unrestricted upload
Weaknesses CWE-284
CWE-434
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Technostrobe Hi-led-wr120-g2 Hi-led-wr120-g2 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-06T18:05:52.840Z

Reserved: 2026-04-04T14:41:15.498Z

Link: CVE-2026-5573

cve-icon Vulnrichment

Updated: 2026-04-06T18:05:47.986Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-05T15:16:41.880

Modified: 2026-04-30T20:49:23.967

Link: CVE-2026-5573

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-06T21:56:38Z

Weaknesses