Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/kakarotossj3/CVEs/blob/main/Hitron/XSS |
|
Tue, 17 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 11 Feb 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hitrontech
Hitrontech hi3120 Hitrontech hi3120 Firmware |
|
| CPEs | cpe:2.3:h:hitrontech:hi3120:-:*:*:*:*:*:*:* cpe:2.3:o:hitrontech:hi3120_firmware:7.2.4.5.2b1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Hitrontech
Hitrontech hi3120 Hitrontech hi3120 Firmware |
Tue, 10 Feb 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hitron
Hitron hi3120 |
|
| Vendors & Products |
Hitron
Hitron hi3120 |
Mon, 09 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Mon, 09 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Hitron HI3120 v7.2.4.5.2b1 allows stored XSS via the Parental Control option when creating a new filter. The device fails to properly handle inputs, allowing an attacker to inject and execute JavaScript. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-02-17T18:13:17.385Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63354
Updated: 2026-02-09T16:19:56.236Z
Status : Modified
Published: 2026-02-09T15:16:11.070
Modified: 2026-02-17T19:21:55.063
Link: CVE-2025-63354
No data.
OpenCVE Enrichment
Updated: 2026-02-10T12:23:59Z