Junglewise Threat Intelligence

CVE-2026-5569: Technostrobe HI-LED-WR120-G2 broken access control in Endpoint

CVE-2026-5569 · Severity: high · CVSS 7.3 · Published 2026-04-05

Technologies: Technostrobe Hi-Led-Wr120-G2 Firmware, Technostrobe Hi-Led-Wr120-G2. Vendors: Technostrobe.

Executive brief

Technostrobe tower lights, which are critical safety systems used to prevent aircraft from colliding with tall structures like skyscrapers and wind turbines, contain a severe security flaw. An unauthorized person can remotely access the device's management interface to view surveillance data, modify alarm settings, or change user passwords. This could allow an attacker to disable or manipulate aviation safety lighting, posing a significant risk to public safety and infrastructure operations.

Technical details

Technostrobe HI-LED-WR120-G2 firmware version 5.5.0.1R6.03.30 suffers from multiple Broken Access Control (BAC) vulnerabilities (CWE-284, CWE-266) within its web-based management interface. The application fails to enforce authentication or authorization checks on several critical endpoints under the /Technostrobe/ directory, including surveillance pages, alarm configurations, and password management functions. A remote, unauthenticated attacker can exploit these flaws to monitor system status, modify safety parameters, or perform a full account takeover by resetting any user's password. As of the disclosure date, the vendor has not responded to reports, and no patch is currently available.

Affected products

  • Technostrobe HI-LED-WR120-G2 firmware 5.5.0.1R6.03.30

Timeline

  • 2026-04-05: disclosed: Initial public disclosure via VulDB and researcher GitHub
  • 2026-04-05: advisory: CVE-2026-5569 assigned

References

Related threats