CVE-2026-5570 is an improper authentication vulnerability identified in Technostrobe HI-LED-WR120-G2 version 5.5.0.1R6.03.30, specifically affecting the index_config function in the /LoginCB file. The vulnerability allows unauthenticated attackers to exploit the device remotely without any special access or user interaction required. This represents a critical authentication bypass with potential consequences for device security. The vulnerability carries a CVSS score of 7.3 (HIGH) with a network-based attack vector that requires low complexity and no privileges to execute. An attacker can gain limited access to confidentiality, integrity, and availability of the affected system. The FAUCET Risk Score of 47.0 out of 100 indicates moderate to significant risk requiring organizational attention. Exploitation status shows the vulnerability is not currently tracked in CISA's Known Exploited Vulnerabilities catalog and has not appeared on the Hot List, suggesting limited active exploitation in the wild. However, the exploit has been publicly disclosed, making it potentially available to threat actors. The vendor was notified during the disclosure process but did not respond, indicating a lack of official patching support for affected systems. Organizations running this firmware version should prioritize upgrading or implementing network-level mitigations to restrict access to the affected device.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.5.0.1r6.03.30CPE matchmatch criteria | cpe:2.3:o:technostrobe:hi-led-wr120-g2_firmware:5.5.0.1r6.03.30:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.