Impact
The deletefile function in the FsBrowseClean component omits the authorization check when the dir/path argument is manipulated, allowing an attacker to trigger the deletion of arbitrary files on the device. This flaw can be exploited from a remote location and results in the loss of critical data or the device’s ability to operate properly.
Affected Systems
Technostrobe HI-LED-WR120‑G2 routers running firmware version 5.5.0.1R6.03.30 are affected. The vulnerability is specific to the FsBrowseClean module within this product line.
Risk and Exploitability
The CVSS score of 6.9 places this issue in the medium‑to‑high severity range. Exploitation is feasible from a remote position; the exploit has been disclosed publicly and may be used in the wild. No EPSS data is available, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. With no official patch released and the vendor not responding to the disclosure, the risk remains significant for organizations still running the affected firmware.
OpenCVE Enrichment