Executive brief
Technostrobe HI-LED-WR120-G2 is a lighting controller used on broadcast and aviation towers to ensure compliance with safety regulations. A security flaw allows unauthorized individuals to upload arbitrary files to the device over the network without needing a password. This could allow an attacker to take full control of the device, potentially disabling critical safety lighting or using the controller as a foothold to attack other parts of the network.
Technical details
An unauthenticated arbitrary file upload vulnerability exists in the Technostrobe HI-LED-WR120-G2 firmware version 5.5.0.1R6.03.30. The flaw is located in the '/fs' file system handler, where the 'cwd' argument can be manipulated to specify upload paths. Because the application fails to validate user authorization or restrict file types/locations, a remote attacker can upload malicious scripts or binaries to the web root. This can lead to Remote Code Execution (RCE) and full system compromise. A public exploit (PoC) is available, and the vendor has reportedly not responded to disclosure attempts.
Affected products
- Technostrobe HI-LED-WR120-G2 firmware 5.5.0.1R6.03.30
Timeline
- 2026-04-05: disclosed: Initial disclosure via VulDB and NVD
- 2026-04-05: advisory