Junglewise Threat Intelligence

CVE-2025-66963: Hitron HI3120 insufficient session expiration in logout function

CVE-2025-66963 · Severity: medium · CVSS 5.5 · Published 2025-12-15

Executive brief

A security issue exists in Hitron HI3120 networking devices where the logout function fails to properly terminate a user's session. This could allow an unauthorized person with physical or local access to the device to continue using a previous user's session even after they believe they have logged out. This may lead to the exposure of sensitive configuration data or unauthorized access to device settings.

Technical details

An insufficient session expiration vulnerability (CWE-613) exists in the Hitron HI3120 firmware version 7.2.4.5.2b1. The logout mechanism within the web interface (index.html) fails to invalidate the session token or terminate the active session on the server side. A local attacker with access to the same workstation or network interface can exploit this by navigating back to the administrative pages after a legitimate user has clicked 'Logout,' gaining unauthorized access to sensitive information and device management functions. The vulnerability was identified in the web management component at /webpages/index.html.

Affected products

  • Hitron HI3120 firmware 7.2.4.5.2b1

Timeline

  • 2025-12-15: advisory: CVE published by NVD/MITRE

References