CVE-2025-63354

Hitron HI3120 v7.2.4.5.2b1 allows stored XSS via the Parental Control option when creating a new filter. The device fails to properly handle inputs, allowing an attacker to inject and execute JavaScript.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hitrontech:hi3120_firmware:7.2.4.5.2b1:*:*:*:*:*:*:*
cpe:2.3:h:hitrontech:hi3120:-:*:*:*:*:*:*:*

History

17 Feb 2026, 19:21

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.6
v2 : unknown
v3 : 4.8
Summary
  • (es) Hitron HI3120 v7.2.4.5.2b1 permite XSS almacenado a través de la opción Control Parental al crear un nuevo filtro. El dispositivo no gestiona correctamente las entradas, permitiendo a un atacante inyectar y ejecutar JavaScript.

11 Feb 2026, 18:30

Type Values Removed Values Added
CPE cpe:2.3:o:hitrontech:hi3120_firmware:7.2.4.5.2b1:*:*:*:*:*:*:*
cpe:2.3:h:hitrontech:hi3120:-:*:*:*:*:*:*:*
References () https://github.com/kakarotossj3/CVEs/blob/main/Hitron/XSS - () https://github.com/kakarotossj3/CVEs/blob/main/Hitron/XSS - Third Party Advisory
First Time Hitrontech
Hitrontech hi3120
Hitrontech hi3120 Firmware

09 Feb 2026, 18:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.6
CWE CWE-79

09 Feb 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-09 15:16

Updated : 2026-02-17 19:21


NVD link : CVE-2025-63354

Mitre link : CVE-2025-63354

CVE.ORG link : CVE-2025-63354


JSON object : View

Products Affected

hitrontech

  • hi3120_firmware
  • hi3120
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')