Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.9

Technostrobe HI-LED-WR120-G2 allows attackers to delete files without permission

CVE-2026-5574
Summary

A vulnerability in the Technostrobe HI-LED-WR120-G2 software allows an attacker to delete files without needing permission. This could lead to unauthorized changes to the system, potentially causing data loss or disruption. Technostrobe has not yet responded to a report of this issue, so users should be cautious and consider taking steps to protect their data.

Original title
A security vulnerability has been detected in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Affected is the function deletefile of the component FsBrowseClean. The manipulation of the argument dir/...
Original description
A security vulnerability has been detected in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Affected is the function deletefile of the component FsBrowseClean. The manipulation of the argument dir/path leads to missing authorization. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
nvd CVSS2.0 6.4
nvd CVSS3.1 6.5
nvd CVSS4.0 6.9
Vulnerability type
CWE-862 Missing Authorization
CWE-863 Incorrect Authorization
Published: 5 Apr 2026 · Updated: 5 Apr 2026 · First seen: 5 Apr 2026