Executive brief
A vulnerability exists in Technostrobe HI-LED-WR120-G2 obstruction light controllers, which are used to manage safety lighting on tall structures like cranes and towers. An unauthorized person can remotely delete critical system files without needing a password. This could lead to a complete system failure, loss of safety lighting, or the destruction of logs and evidence after a security breach.
Technical details
A missing authorization vulnerability (CWE-862) exists in the 'deletefile' function of the 'FsBrowseClean' component in Technostrobe HI-LED-WR120-G2 firmware version 5.5.0.1R6.03.30. The vulnerability is triggered by manipulating the 'dir/path' argument in a remote request. Because the endpoint does not require authentication, a remote attacker can delete arbitrary files on the device's filesystem. This can be used to cause a permanent Denial of Service (DoS) by deleting boot or configuration files, or to cover tracks by deleting log files. A public exploit (PoC) is available, and the vendor has reportedly not responded to disclosure attempts.
Affected products
- Technostrobe HI-LED-WR120-G2 firmware 5.5.0.1R6.03.30
Timeline
- 2026-04-05: disclosed: Public disclosure of the vulnerability and exploit.
- 2026-04-05: advisory: Initial advisory published by VulDB.