CVE-2025-63354: Hitrontech HI3120 Firmware

Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Hitron HI3120 v7.2.4.5.2b1 allows stored XSS via the Parental Control option when creating a new filter. The device fails to properly handle inputs, allowing an attacker to inject and execute JavaScript.

Affected products

  • Hitrontech HI3120 Firmware: version 7.2.4.5.2b1 only

Published 2026-02-09. Last modified 2026-06-17.