Description
A security vulnerability has been detected in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Affected is the function deletefile of the component FsBrowseClean. The manipulation of the argument dir/path leads to missing authorization. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-04-05
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote File Deletion
Action: Apply Firmware Update
AI Analysis

Impact

The deletefile function in the FsBrowseClean component omits the authorization check when the dir/path argument is manipulated, allowing an attacker to trigger the deletion of arbitrary files on the device. This flaw can be exploited from a remote location and results in the loss of critical data or the device’s ability to operate properly.

Affected Systems

Technostrobe HI-LED-WR120‑G2 routers running firmware version 5.5.0.1R6.03.30 are affected. The vulnerability is specific to the FsBrowseClean module within this product line.

Risk and Exploitability

The CVSS score of 6.9 places this issue in the medium‑to‑high severity range. Exploitation is feasible from a remote position; the exploit has been disclosed publicly and may be used in the wild. No EPSS data is available, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. With no official patch released and the vendor not responding to the disclosure, the risk remains significant for organizations still running the affected firmware.

Generated by OpenCVE AI on April 5, 2026 at 18:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest firmware update from Technostrobe that addresses the deletefile authorization issue.
  • If a firmware update is unavailable, block remote access to the device or restrict the FsBrowseClean functionality through device configuration or firewall rules.
  • Place the device on a segregated network segment or apply VLAN restrictions to limit inbound traffic.
  • Enable logging and regularly review system logs for unexpected deletefile operations or other anomalous activity.
  • Consider replacing the affected device if it remains critical and no patch path is provided.

Generated by OpenCVE AI on April 5, 2026 at 18:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 01 May 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Technostrobe hi-led-wr120-g2 Firmware
CPEs cpe:2.3:h:technostrobe:hi-led-wr120-g2:-:*:*:*:*:*:*:*
cpe:2.3:o:technostrobe:hi-led-wr120-g2_firmware:5.5.0.1r6.03.30:*:*:*:*:*:*:*
Vendors & Products Technostrobe hi-led-wr120-g2 Firmware

Tue, 07 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Technostrobe
Technostrobe hi-led-wr120-g2
Vendors & Products Technostrobe
Technostrobe hi-led-wr120-g2

Mon, 06 Apr 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 05 Apr 2026 15:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Affected is the function deletefile of the component FsBrowseClean. The manipulation of the argument dir/path leads to missing authorization. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Technostrobe HI-LED-WR120-G2 FsBrowseClean deletefile authorization
Weaknesses CWE-862
CWE-863
References
Metrics cvssV2_0

{'score': 6.4, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Technostrobe Hi-led-wr120-g2 Hi-led-wr120-g2 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-06T16:16:52.463Z

Reserved: 2026-04-04T14:41:18.833Z

Link: CVE-2026-5574

cve-icon Vulnrichment

Updated: 2026-04-06T16:16:44.185Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-05T15:16:42.820

Modified: 2026-05-01T13:19:42.050

Link: CVE-2026-5574

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-06T21:56:37Z

Weaknesses