Junglewise Threat Intelligence

CVE-2026-5570: Technostrobe HI-LED-WR120-G2 auth bypass in /LoginCB

CVE-2026-5570 · Severity: high · CVSS 7.3 · Published 2026-04-05

Technologies: Technostrobe Hi-Led-Wr120-G2 Firmware, Technostrobe Hi-Led-Wr120-G2. Vendors: Technostrobe.

Executive brief

A vulnerability exists in the Technostrobe HI-LED-WR120-G2, a controller used to manage aviation obstruction lighting on tall structures like towers. An attacker can bypass the login screen to gain unauthorized access to the device's configuration and light control panels. This could allow an unauthorized user to modify safety-critical lighting settings, potentially impacting aviation safety and regulatory compliance.

Technical details

An authentication bypass vulnerability exists in Technostrobe HI-LED-WR120-G2 firmware version 5.5.0.1R6.03.30. The flaw is located in the index_config function within the /LoginCB file, where authentication is improperly enforced on the client side rather than the server side. By manipulating HTTP responses (e.g., using a proxy to modify a 'denied' response to 'success') or accessing specific endpoints directly, a remote, unauthenticated attacker can bypass the login mechanism. This grants access to the configuration panel and light control board. The vendor has reportedly not responded to disclosure attempts, and a public exploit exists.

Affected products

  • Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30

Timeline

  • 2026-04-05: disclosed: Vulnerability publicly disclosed via VulDB and GitHub.
  • 2026-04-05: advisory

References

Related threats