CVE-2026-5573 affects Technostrobe HI-LED-WR120-G2 version 5.5.0.1R6.03.30 and involves an unrestricted file upload vulnerability in the /fs endpoint. The flaw exists in an unknown function that fails to properly validate the "cwd" (current working directory) argument, allowing attackers to bypass upload restrictions. This vulnerability carries a CVSS score of 7.3 (HIGH) with a network-based attack vector requiring no authentication or user interaction, making it relatively straightforward to exploit. The vulnerability is currently not listed on the Known Exploited Vulnerabilities (KEV) catalog and shows no signs of active exploitation in the wild, though proof-of-concept code has been publicly disclosed. The vendor failed to respond to early disclosure attempts, limiting the availability of official patches and increasing the risk of adoption by threat actors once awareness spreads.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.5.0.1r6.03.30CPE matchmatch criteria | cpe:2.3:o:technostrobe:hi-led-wr120-g2_firmware:5.5.0.1r6.03.30:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.