Junglewise Threat Intelligence

CVE-2026-5574: Technostrobe HI-LED-WR120-G2 unauthenticated file deletion in FsBrowseClean

CVE-2026-5574 · Severity: medium · CVSS 6.5 · Published 2026-04-05

Technologies: Technostrobe Hi-Led-Wr120-G2 Firmware, Technostrobe Hi-Led-Wr120-G2. Vendors: Technostrobe.

Executive brief

A vulnerability exists in Technostrobe HI-LED-WR120-G2 obstruction light controllers, which are used to manage safety lighting on tall structures like cranes and towers. An unauthorized person can remotely delete critical system files without needing a password. This could lead to a complete system failure, loss of safety lighting, or the destruction of logs and evidence after a security breach.

Technical details

A missing authorization vulnerability (CWE-862) exists in the 'deletefile' function of the 'FsBrowseClean' component in Technostrobe HI-LED-WR120-G2 firmware version 5.5.0.1R6.03.30. The vulnerability is triggered by manipulating the 'dir/path' argument in a remote request. Because the endpoint does not require authentication, a remote attacker can delete arbitrary files on the device's filesystem. This can be used to cause a permanent Denial of Service (DoS) by deleting boot or configuration files, or to cover tracks by deleting log files. A public exploit (PoC) is available, and the vendor has reportedly not responded to disclosure attempts.

Affected products

  • Technostrobe HI-LED-WR120-G2 firmware 5.5.0.1R6.03.30

Timeline

  • 2026-04-05: disclosed: Public disclosure of the vulnerability and exploit.
  • 2026-04-05: advisory: Initial advisory published by VulDB.

References

Related threats