Executive brief
Technostrobe HI-LED-WR120-G2, a lighting controller used for industrial and aviation obstruction lighting, is vulnerable to a security flaw that could allow an attacker to trick a logged-in administrator into performing unintended actions. By convincing a user to click a malicious link or visit a compromised website, an attacker could change device settings or configurations without the user's consent. This could lead to unauthorized operational changes to critical infrastructure lighting systems.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of Technostrobe HI-LED-WR120-G2 firmware version 5.5.0.1R6.03.30. The flaw stems from missing authorization checks and a lack of anti-CSRF tokens in an unspecified function. A remote attacker can exploit this by inducing an authenticated user to submit a specially crafted web request. Successful exploitation allows the attacker to perform state-changing operations with the privileges of the victim. A public exploit (PoC) has been released, and the vendor has reportedly not responded to disclosure attempts.
Affected products
- Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30
Timeline
- 2026-04-05: disclosed: Initial disclosure via VulDB
- 2026-04-05: advisory: CVE-2026-5572 assigned