Hitrontech develops cable modem and network gateway products, particularly the CODA line, that sit in the access tier of residential and small-business networks. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and center on a durable pattern of input-handling flaws—cross-site scripting and OS command injection—alongside cleartext transmission and credential-exposure weaknesses that are endemic to embedded network appliances with web management interfaces. Current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hitrontech over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25017HIGH Hitron CHITA 7.2.2.0.3b6-CD devices contain a command injection vulnerability via the Device/DDNS ddnsUsername field. | Apr 1, 2022 | 8.8 | 44 | NO | NO |
CVE-2023-30604CRITICAL It is identified a vulnerability of insufficient authentication in the system configuration interface of Hitron Technologies CODA-5310. An unauthorized remote attacker can exploit | Jun 2, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-30603CRITICAL Hitron Technologies CODA-5310 Telnet function with the default account and password, and there is no warning or prompt to ask users to change the default password and account. An u | Jun 2, 2023 | 9.8 | 28 | NO | NO |
CVE-2024-25730CRITICAL Hitron CODA-4582 and CODA-4589 devices have default PSKs that are generated from 5-digit hex values concatenated with a "Hitron" substring, resulting in insufficient entropy (only | Feb 23, 2024 | 9.8 | 24 | NO | NO |
CVE-2025-66963MEDIUM An issue in Hitron HI3120 v.7.2.4.5.2b1 allows a local attacker to obtain sensitive information via the Logout option in the index.html | Dec 15, 2025 | 5.5 | 22 | NO | NO |
CVE-2023-30602HIGH Hitron Technologies CODA-5310’s Telnet function transfers sensitive data in plaintext. An unauthenticated remote attacker can exploit this vulnerability to access credentials of no | Jun 2, 2023 | 7.5 | 22 | NO | NO |
CVE-2022-47617HIGH Hitron CODA-5310 has hard-coded encryption/decryption keys in the program code. A remote attacker authenticated as an administrator can decrypt system files using the hard-coded ke | Jun 2, 2023 | 7.2 | 21 | NO | NO |
CVE-2022-47616HIGH Hitron CODA-5310 has insufficient filtering for specific parameters in the connection test function. A remote attacker authenticated as an administrator, can use the management pag | Jun 2, 2023 | 7.2 | 21 | NO | NO |
CVE-2014-10069HIGH Hitron CVE-30360 devices use a 578A958E3DD933FC DES key that is shared across different customers' installations, which makes it easier for attackers to obtain sensitive informatio | Jan 7, 2018 | 7.5 | 20 | NO | NO |
CVE-2025-63354MEDIUM Hitron HI3120 v7.2.4.5.2b1 allows stored XSS via the Parental Control option when creating a new filter. The device fails to properly handle inputs, allowing an attacker to inject | Feb 9, 2026 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hitrontech.
Media articles that mention a CVE ID that affects a product developed by Hitrontech — matched by CVE ID, not by vendor name.