Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5572

21
FAUCET Score

CVE-2026-5572 is a cross-site request forgery (CSRF) vulnerability affecting Technostrobe HI-LED-WR120-G2 version 5.5.0.1R6.03.30. The flaw resides in an unidentified function within the product and allows an attacker to perform unauthorized actions on behalf of authenticated users. The vulnerability has a CVSS 3.1 score of 4.3 (Medium severity) with a network-based attack vector requiring no privileges but necessitating user interaction. The attack has low complexity and results in integrity impact with no confidentiality or availability compromise. This modest severity rating is reflected in the low EPSS score of 0.000050000, indicating minimal real-world exploitation likelihood. Exploit code has been released publicly, though there is currently no evidence of active exploitation in the wild. The vulnerability is not tracked on the CISA KEV catalog and remains inactive on threat intelligence hot lists. Notably, the vendor declined to engage with the disclosure process, leaving this vulnerability unpatched and presenting an ongoing risk to deployed instances.

Impacted Technologies

VendorProductVersion(s)CPE
5.5.0.1r6.03.30CPE matchmatch criteria
cpe:2.3:o:technostrobe:hi-led-wr120-g2_firmware:5.5.0.1r6.03.30:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

2.1LOW

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
PASSIVE
VS Confidentiality
NONE
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.23%
Probability of exploitation in next 30 days
EPSS Percentile
14.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0023 is in the 15th percentile among its peer group of 26,219 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryworkaround availablevia nvd_reference
View patch

References

github.com / shiky8/my--cve-vulnerability-research/blob/main/my_VulnDB_cves/CVE-TECHNOSTROBE-04-CSRF.md
ExploitMitigationThird Party Advisory
vuldb.com / submit/783325
Third Party AdvisoryVDB Entry
vuldb.com / vuln/355342
Third Party AdvisoryVDB Entry
vuldb.com / vuln/355342/cti
Permissions RequiredVDB Entry