Gregory Cardoso

2 exploits Active since Dec 2025
CVE-2025-63354 WRITEUP MEDIUM WRITEUP
Hitron HI3120 <7.2.4.5.2b1 - XSS
Hitron HI3120 v7.2.4.5.2b1 allows stored XSS via the Parental Control option when creating a new filter. The device fails to properly handle inputs, allowing an attacker to inject and execute JavaScript.
CVSS 4.8
CVE-2025-66963 WRITEUP MEDIUM WRITEUP
Hitrontech Hi3120 Firmware - Information Disclosure
An issue in Hitron HI3120 v.7.2.4.5.2b1 allows a local attacker to obtain sensitive information via the Logout option in the index.html
CVSS 5.5