Junglewise Threat Intelligence

CVE-2026-5573: Technostrobe HI-LED-WR120-G2 unauthenticated file upload in /fs

CVE-2026-5573 · Severity: high · CVSS 7.3 · Published 2026-04-05

Technologies: Technostrobe Hi-Led-Wr120-G2 Firmware, Technostrobe Hi-Led-Wr120-G2. Vendors: Technostrobe.

Executive brief

Technostrobe HI-LED-WR120-G2 is a lighting controller used on broadcast and aviation towers to ensure compliance with safety regulations. A security flaw allows unauthorized individuals to upload arbitrary files to the device over the network without needing a password. This could allow an attacker to take full control of the device, potentially disabling critical safety lighting or using the controller as a foothold to attack other parts of the network.

Technical details

An unauthenticated arbitrary file upload vulnerability exists in the Technostrobe HI-LED-WR120-G2 firmware version 5.5.0.1R6.03.30. The flaw is located in the '/fs' file system handler, where the 'cwd' argument can be manipulated to specify upload paths. Because the application fails to validate user authorization or restrict file types/locations, a remote attacker can upload malicious scripts or binaries to the web root. This can lead to Remote Code Execution (RCE) and full system compromise. A public exploit (PoC) is available, and the vendor has reportedly not responded to disclosure attempts.

Affected products

  • Technostrobe HI-LED-WR120-G2 firmware 5.5.0.1R6.03.30

Timeline

  • 2026-04-05: disclosed: Initial disclosure via VulDB and NVD
  • 2026-04-05: advisory

References

Related threats