CVE-2025-34260: fallo de gravedad media en Advantech Co., Ltd. WISE-DeviceOn Server
Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via action/schedule
Publicada el · Actualizada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.1epss 0.3%
probabilidad de explotación
0.3%top 85% de las CVE
explotación observada
noninguna fuente lo reporta
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/schedule endpoint. When an authenticated user adds a schedule to an existing task, the schedule name is stored and later rendered in schedule listings without HTML sanitation. An attacker can inject malicious script into the schedule name, which is then executed in the browser context of users who view or interact with the affected schedule, potentially enabling session compromise and unauthorized actions as the victim.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Productos afectados
Advantech Co., Ltd. · WISE-DeviceOn ServerCVEs relacionadas — Advantech Co., Ltd. WISE-DeviceOn Server
En el mismo producto, de las más peligrosas a las menos.
CVE-2025-34256CRITICALAdvantech WISE-DeviceOn Server < 5.4 Hard-coded JWT Key Authentication BypassEPSS 0.7%CVE-2025-34259MEDIUMAdvantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devicemap/buildingEPSS 0.3%CVE-2025-34261MEDIUMAdvantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devicegroups/EPSS 0.3%CVE-2025-34257MEDIUMAdvantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via action/definedEPSS 0.3%CVE-2025-34266MEDIUMAdvantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via plugin-config/addins/menusEPSS 0.2%CVE-2025-34262MEDIUMAdvantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devices/name/{agent_id}EPSS 0.2%
Referencias
https://advcloudfiles.advantech.com/cms/2ca1b071-fd78-4d7f-8a2a-7b4537a95d19/Security%20Advisory%20PDF%20File/SECURITY-ADVISORY----DeviceOn-20251208-2.pdfhttps://docs.deviceon.advantech.com/docs/resource/https://www.vulncheck.com/advisories/advantech-wise-deviceon-server-authenticated-stored-xss-via-action-schedule