PT-2025-49283 · Advantech · Wise-Deviceon Server

Alex Williams

·

Published

2025-12-05

·

Updated

2025-12-05

·

CVE-2025-34262

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Advantech WISE-DeviceOn Server versions prior to 5.4
Description The software contains a stored cross-site scripting (XSS) issue in the /rmm/v1/devices/name/{agent id} API endpoint. An authenticated user renaming a device allows for the injection of malicious script via the new name value. This script is executed in the browser of users viewing or interacting with the affected device, potentially leading to session compromise and unauthorized actions.
Recommendations Update to a version prior to 5.4.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-34262

Affected Products

Wise-Deviceon Server