Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5571

28
FAUCET Score

CVE-2026-5571 is an information disclosure vulnerability affecting Technostrobe HI-LED-WR120-G2 version 5.5.0.1R6.03.30, specifically in the Configuration Data Handler component's file system (/fs) functionality. The vulnerability allows manipulation of file-related arguments to expose sensitive information without requiring authentication or user interaction. The vulnerability carries a CVSS 3.1 score of 5.3 (Medium severity) with a network-based attack vector requiring low complexity. The impact is limited to information disclosure, with no integrity or availability effects. The EPSS score of 0.00039 indicates this vulnerability ranks lower than 99.88 percent of all known CVEs in terms of statistical exploitation likelihood. Exploitation code is publicly available, presenting a potential risk despite currently low community attention. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog, and there is no evidence of active real-world exploitation at this time. The vendor, Technostrobe, was notified early in the disclosure process but provided no response, leaving the issue unresolved as of this briefing.

Impacted Technologies

VendorProductVersion(s)CPE
5.5.0.1r6.03.30CPE matchmatch criteria
cpe:2.3:o:technostrobe:hi-led-wr120-g2_firmware:5.5.0.1r6.03.30:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

5.5MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.47%
Probability of exploitation in next 30 days
EPSS Percentile
38.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0047 is in the 17th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryworkaround availablevia nvd_reference
View patch

References

github.com / shiky8/my--cve-vulnerability-research/blob/main/my_VulnDB_cves/CVE-TECHNOSTROBE-03-InfoDisclosure.md
ExploitMitigationThird Party Advisory
vuldb.com / submit/783324
Third Party AdvisoryVDB Entry
vuldb.com / vuln/355341
Third Party AdvisoryVDB Entry
vuldb.com / vuln/355341/cti
Permissions RequiredVDB Entry