hitrontech records
13 published records for vendor hitrontech.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-306 Missing Authentication for Critical Function1
- CWE-310 Cryptographic Issues1
- CWE-319 Cleartext Transmission of Sensitive Information1
- CWE-331 Insufficient Entropy1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
44Plan | CVE-2022-25017No exploit | Hitron CHITA 7.2.2.0.3b6-CD devices contain a command injection vulnerability via the Device/DDNS ddnsUsername field.hitrontech · chita firmware · CWE-78 | High8.8 | — | 29.1% | Apr 1, 2022 |
39Monitor | CVE-2023-30604No exploit | Hitron Technologies Inc. CODA-5310 - Broken Access Controlhitrontech · coda-5310 firmware · CWE-306 | Critical9.8 | — | 0.9% | Jun 2, 2023 |
39Monitor | CVE-2024-25730No exploit | Hitron CODA-4582 and CODA-4589 devices have default PSKs that are generated from 5-digit hex values concatenated with a "Hitron" substring, hitrontech · coda-4582u firmware · CWE-331 | Critical9.8 | — | 0.9% | Feb 23, 2024 |
39Monitor | CVE-2023-30603No exploit | Hitron Technologies Inc. CODA-5310 - Using default credentialshitrontech · coda-5310 firmware · CWE-1392 | Critical9.8 | — | 0.8% | Jun 2, 2023 |
31Monitor | CVE-2014-10069Proof of concept | Hitron CVE-30360 devices use a 578A958E3DD933FC DES key that is shared across different customers' installations, which makes it easier for hitrontech · cve-30360 firmware · CWE-310 | High7.5 | — | 4.0% | Jan 7, 2018 |
30Monitor | CVE-2023-30602No exploit | Hitron Technologies Inc. CODA-5310 - Insecure service Telnethitrontech · coda-5310 firmware · CWE-319 | High7.5 | — | 0.5% | Jun 2, 2023 |
28Monitor | CVE-2022-47616No exploit | Hitron Technologies Inc. CODA-5310 - Remote Command Executionhitrontech · coda-5310 firmware · CWE-78 | High7.2 | — | 1.3% | Jun 2, 2023 |
28Monitor | CVE-2022-47617No exploit | Hitron Technologies Inc. CODA-5310 - Hard-coded Cryptographic Keyhitrontech · coda-5310 firmware · CWE-798 | High7.2 | — | 0.5% | Jun 2, 2023 |
22Monitor | CVE-2025-66963No exploit | An issue in Hitron HI3120 v.7.2.4.5.2b1 allows a local attacker to obtain sensitive information via the Logout option in the index.htmlhitrontech · hi3120 firmware · CWE-200 | Medium5.5 | — | 0.1% | Dec 15, 2025 |
21Monitor | CVE-2020-8824No exploit | Hitron CODA-4582U 7.1.1.30 devices allow XSS via a Managed Device name on the Wireless > Access Control > Add Managed Device screen.hitrontech · coda-4582u firmware · CWE-79 | Medium5.4 | — | 0.6% | Feb 19, 2020 |
20Monitor | CVE-2024-28089No exploit | Hitron CODA-4582 2AHKM-CODA4589 7.2.4.5.1b8 devices allow a remote attacker within Wi-Fi proximity (who has access to the router admin panelCWE-79 | Medium5.2 | — | 0.7% | Mar 9, 2024 |
20Monitor | CVE-2024-31973No exploit | Hitron CODA-4582 2AHKM-CODA4589 7.2.4.5.1b8 devices allow a remote attacker within Wi-Fi proximity to conduct stored XSS attacks via the 'NeCWE-79 | Medium5.2 | — | 0.5% | Oct 30, 2024 |
19Monitor | CVE-2025-63354No exploit | Hitron HI3120 v7.2.4.5.2b1 allows stored XSS via the Parental Control option when creating a new filter.hitrontech · hi3120 firmware · CWE-79 | Medium4.8 | — | 0.2% | Feb 9, 2026 |
- CVE-2022-2501744Plan
Hitron CHITA 7.2.2.0.3b6-CD devices contain a command injection vulnerability via the Device/DDNS ddnsUsername field.
HighCVSS 8.8No exploitEPSS 29%hitrontech · chita firmwareApr 1, 2022
- CVE-2023-3060439Monitor
Hitron Technologies Inc. CODA-5310 - Broken Access Control
CriticalCVSS 9.8No exploitEPSS 1%hitrontech · coda-5310 firmwareJun 2, 2023
- CVE-2024-2573039Monitor
Hitron CODA-4582 and CODA-4589 devices have default PSKs that are generated from 5-digit hex values concatenated with a "Hitron" substring,
CriticalCVSS 9.8No exploitEPSS 1%hitrontech · coda-4582u firmwareFeb 23, 2024
- CVE-2023-3060339Monitor
Hitron Technologies Inc. CODA-5310 - Using default credentials
CriticalCVSS 9.8No exploitEPSS 1%hitrontech · coda-5310 firmwareJun 2, 2023
- CVE-2014-1006931Monitor
Hitron CVE-30360 devices use a 578A958E3DD933FC DES key that is shared across different customers' installations, which makes it easier for
HighCVSS 7.5Proof of conceptEPSS 4%hitrontech · cve-30360 firmwareJan 7, 2018
- CVE-2023-3060230Monitor
Hitron Technologies Inc. CODA-5310 - Insecure service Telnet
HighCVSS 7.5No exploitEPSS 0%hitrontech · coda-5310 firmwareJun 2, 2023
- CVE-2022-4761628Monitor
Hitron Technologies Inc. CODA-5310 - Remote Command Execution
HighCVSS 7.2No exploitEPSS 1%hitrontech · coda-5310 firmwareJun 2, 2023
- CVE-2022-4761728Monitor
Hitron Technologies Inc. CODA-5310 - Hard-coded Cryptographic Key
HighCVSS 7.2No exploitEPSS 1%hitrontech · coda-5310 firmwareJun 2, 2023
- CVE-2025-6696322Monitor
An issue in Hitron HI3120 v.7.2.4.5.2b1 allows a local attacker to obtain sensitive information via the Logout option in the index.html
MediumCVSS 5.5No exploitEPSS 0%hitrontech · hi3120 firmwareDec 15, 2025
- CVE-2020-882421Monitor
Hitron CODA-4582U 7.1.1.30 devices allow XSS via a Managed Device name on the Wireless > Access Control > Add Managed Device screen.
MediumCVSS 5.4No exploitEPSS 1%hitrontech · coda-4582u firmwareFeb 19, 2020
- CVE-2024-2808920Monitor
Hitron CODA-4582 2AHKM-CODA4589 7.2.4.5.1b8 devices allow a remote attacker within Wi-Fi proximity (who has access to the router admin panel
MediumCVSS 5.2No exploitEPSS 1%Mar 9, 2024
- CVE-2024-3197320Monitor
Hitron CODA-4582 2AHKM-CODA4589 7.2.4.5.1b8 devices allow a remote attacker within Wi-Fi proximity to conduct stored XSS attacks via the 'Ne
MediumCVSS 5.2No exploitEPSS 0%Oct 30, 2024
- CVE-2025-6335419Monitor
Hitron HI3120 v7.2.4.5.2b1 allows stored XSS via the Parental Control option when creating a new filter.
MediumCVSS 4.8No exploitEPSS 0%hitrontech · hi3120 firmwareFeb 9, 2026