Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5570

34
FAUCET Score

CVE-2026-5570 is an improper authentication vulnerability identified in Technostrobe HI-LED-WR120-G2 version 5.5.0.1R6.03.30, specifically affecting the index_config function in the /LoginCB file. The vulnerability allows unauthenticated attackers to exploit the device remotely without any special access or user interaction required. This represents a critical authentication bypass with potential consequences for device security. The vulnerability carries a CVSS score of 7.3 (HIGH) with a network-based attack vector that requires low complexity and no privileges to execute. An attacker can gain limited access to confidentiality, integrity, and availability of the affected system. The FAUCET Risk Score of 47.0 out of 100 indicates moderate to significant risk requiring organizational attention. Exploitation status shows the vulnerability is not currently tracked in CISA's Known Exploited Vulnerabilities catalog and has not appeared on the Hot List, suggesting limited active exploitation in the wild. However, the exploit has been publicly disclosed, making it potentially available to threat actors. The vendor was notified during the disclosure process but did not respond, indicating a lack of official patching support for affected systems. Organizations running this firmware version should prioritize upgrading or implementing network-level mitigations to restrict access to the affected device.

Impacted Technologies

VendorProductVersion(s)CPE
5.5.0.1r6.03.30CPE matchmatch criteria
cpe:2.3:o:technostrobe:hi-led-wr120-g2_firmware:5.5.0.1r6.03.30:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

5.5MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.60%
Probability of exploitation in next 30 days
EPSS Percentile
45.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0060 is in the 25th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryworkaround availablevia nvd_reference
View patch

References

github.com / shiky8/my--cve-vulnerability-research/blob/main/my_VulnDB_cves/CVE-TECHNOSTROBE-02-AuthBypass.md
ExploitMitigationThird Party Advisory
vuldb.com / submit/783323
Third Party AdvisoryVDB Entry
vuldb.com / vuln/355340
Third Party AdvisoryVDB Entry
vuldb.com / vuln/355340/cti
Permissions RequiredVDB Entry