Executive brief
Technostrobe HI-LED-WR120-G2 is a controller used for managing high-intensity LED lighting systems on towers and tall structures. A security flaw allows unauthorized individuals to remotely access sensitive configuration files from the device without a password. This could lead to the exposure of administrative credentials and internal system settings, potentially allowing an attacker to take full control of the lighting infrastructure.
Technical details
An information disclosure vulnerability exists in the Technostrobe HI-LED-WR120-G2 firmware version 5.5.0.1R6.03.30. The vulnerability is located in the Configuration Data Handler component, specifically within the '/fs' file system endpoint. By manipulating the 'File' argument in a remote request, an unauthenticated attacker can retrieve sensitive files such as '/login.cfg' (containing obfuscated credentials) and MQTT broker configurations. The root cause is improper access control (CWE-284) on the file system interface. While the vendor was notified, no patch has been confirmed, and a public exploit/PoC is available.
Affected products
- Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30
Timeline
- 2026-04-05: advisory: Initial disclosure by VulDB
- 2026-04-05: disclosed: Public exploit made available via GitHub research repository