PT-2025-49279 · Advantech · Wise-Deviceon Server

Alex Williams

·

Published

2025-12-05

·

Updated

2025-12-05

·

CVE-2025-34258

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Advantech WISE-DeviceOn Server versions prior to 5.4
Description The software contains a stored cross-site scripting (XSS) issue in the /rmm/v1/devicemap/plan API endpoint. An attacker can inject malicious script into the name parameter when an authenticated user adds an area to a map entry. This script is then executed in the browser context of users who view or interact with the affected map entry, potentially leading to session compromise and unauthorized actions. The issue occurs because the name parameter is stored and rendered without proper HTML sanitization.
Recommendations Update to version 5.4 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-34258

Affected Products

Wise-Deviceon Server