CVE-2026-5571 is an information disclosure vulnerability affecting Technostrobe HI-LED-WR120-G2 version 5.5.0.1R6.03.30, specifically in the Configuration Data Handler component's file system (/fs) functionality. The vulnerability allows manipulation of file-related arguments to expose sensitive information without requiring authentication or user interaction. The vulnerability carries a CVSS 3.1 score of 5.3 (Medium severity) with a network-based attack vector requiring low complexity. The impact is limited to information disclosure, with no integrity or availability effects. The EPSS score of 0.00039 indicates this vulnerability ranks lower than 99.88 percent of all known CVEs in terms of statistical exploitation likelihood. Exploitation code is publicly available, presenting a potential risk despite currently low community attention. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog, and there is no evidence of active real-world exploitation at this time. The vendor, Technostrobe, was notified early in the disclosure process but provided no response, leaving the issue unresolved as of this briefing.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.5.0.1r6.03.30CPE matchmatch criteria | cpe:2.3:o:technostrobe:hi-led-wr120-g2_firmware:5.5.0.1r6.03.30:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.