---
id: CVE-2026-5570
title: A vulnerability was determined in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30
summary: >-
  A vulnerability was determined in Technostrobe HI-LED-WR120-G2
  5.5.0.1R6.03.30. The affected element is the function index_config of the file
  /LoginCB. This manipulation causes improper authentication. It is possible to
  initiate the atta…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-287
vendor: technostrobe
product: hi-led-wr120-g2_firmware
affected:
  - hi-led-wr120-g2_firmware = 5.5.0.1r6.03.30
published: '2026-04-05'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-5570'
references:
  - url: >-
      https://github.com/shiky8/my--cve-vulnerability-research/blob/main/my_VulnDB_cves/CVE-TECHNOSTROBE-02-AuthBypass.md
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/783323'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/355340'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/355340/cti'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00598
epssPercentile: 0.4734
ingestedAt: '2026-07-24T09:23:51.454Z'
---

## Overview

A vulnerability was determined in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. The affected element is the function index_config of the file /LoginCB. This manipulation causes improper authentication. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `hi-led-wr120-g2_firmware = 5.5.0.1r6.03.30`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
