Impact
A flaw was found in the Technostrobe HI‑LED‑WR120‑G2 firmware 5.5.0.1R6.03.30. By manipulating the "cwd" argument to the file /fs, an attacker can upload arbitrary files without restriction. Because the upload endpoint is reachable externally, the vulnerability can be triggered remotely, potentially allowing the placement of malicious code on the device and leading to remote code execution or other privilege‑escalating actions. The weakness corresponds to improper access control and unrestricted file upload.
Affected Systems
Technostrobe HI‑LED‑WR120‑G2 devices running firmware 5.5.0.1R6.03.30 are affected. No other product or version information is available from the CNA data.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate to high severity, and the exploit is publicly available. The EPSS score is not provided, but the lack of a KEV listing does not diminish the potential risk. Attackers can reach the vulnerable endpoint from the internet and can upload files that may be executed or used to compromise the device. The remote nature of the attack path and the possibility to upload dangerous files elevate the threat level for any deployed HI‑LED‑WR120‑G2 units.
OpenCVE Enrichment