Junglewise Threat Intelligence

CVE-2026-5572: Technostrobe HI-LED-WR120-G2 CSRF in web interface

CVE-2026-5572 · Severity: medium · CVSS 4.3 · Published 2026-04-05

Technologies: Technostrobe Hi-Led-Wr120-G2 Firmware, Technostrobe Hi-Led-Wr120-G2. Vendors: Technostrobe.

Executive brief

Technostrobe HI-LED-WR120-G2, a lighting controller used for industrial and aviation obstruction lighting, is vulnerable to a security flaw that could allow an attacker to trick a logged-in administrator into performing unintended actions. By convincing a user to click a malicious link or visit a compromised website, an attacker could change device settings or configurations without the user's consent. This could lead to unauthorized operational changes to critical infrastructure lighting systems.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of Technostrobe HI-LED-WR120-G2 firmware version 5.5.0.1R6.03.30. The flaw stems from missing authorization checks and a lack of anti-CSRF tokens in an unspecified function. A remote attacker can exploit this by inducing an authenticated user to submit a specially crafted web request. Successful exploitation allows the attacker to perform state-changing operations with the privileges of the victim. A public exploit (PoC) has been released, and the vendor has reportedly not responded to disclosure attempts.

Affected products

  • Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30

Timeline

  • 2026-04-05: disclosed: Initial disclosure via VulDB
  • 2026-04-05: advisory: CVE-2026-5572 assigned

References

Related threats