CVE-2026-5569 Details
Description
A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Impacted is an unknown function of the file /Technostrobe/ of the component Endpoint. The manipulation results in improper access controls. The attack may be performed from remote. The exploit has been made public and could be used. Multiple endpoints are affected. The vendor was contacted early about this disclosure but did not respond in any way.
A broken access control vulnerability has been identified in the Technostrobe HI-LED-WR120-G2 obstruction lighting controller, specifically in version 5.5.0.1R6.03.30. The vulnerability resides within the component Endpoint, in an unknown function of the file /Technostrobe/. This issue allows remote attackers to manipulate access controls, leading to unauthorized access to sensitive administrative endpoints via the device's embedded web management interface.
It is recommended to implement server-side session management, enforce authentication on all administrative routes, and require current passwords for password changes. Additionally, sessions should be bound to IP addresses and user agents.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/shiky8/my--cve-vulnerability-research/blob/main/my_VulnDB_cves/CVE-TECHNOSTROBE-01-BrokenAccessControl.md | [email protected] | ExploitMitigationThird Party Advisory |
| https://vuldb.com/submit/783322 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/vuln/355339 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/vuln/355339/cti | [email protected] | Permissions RequiredVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| technostrobe hi-led-wr120-g2 firmware | 5.5.0.1r6.03.30 |
CPE
Remediation
| |
| technostrobe hi-led-wr120-g2 | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 30, 2026 | Initial Analysis | [email protected] |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Apr 5, 2026 | New CVE Received | [email protected] |