PT-2025-49277 · Advantech · Wise-Deviceon Server

Alex Williams

·

Published

2025-12-05

·

Updated

2026-01-01

·

CVE-2025-34256

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Advantech WISE-DeviceOn Server versions prior to 5.4
Description The software uses a static HS512 HMAC secret for signing EIRMMToken JWTs across all installations. This allows a remote unauthenticated attacker to generate forged JWTs containing a valid email claim, enabling impersonation of any DeviceOn account, including the root super admin. Successful exploitation grants full administrative control of the DeviceOn instance and allows code execution on managed agents through the software’s remote management features. The API endpoint is vulnerable to accepting forged JWTs. The vulnerable parameter is the email claim within the JWT.
Recommendations Versions prior to 5.4 should be updated. Restrict access to the software as a temporary mitigation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-34256

Affected Products

Wise-Deviceon Server