CVE-2025-34262: fallo de gravedad media en Advantech Co., Ltd. WISE-DeviceOn Server
Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devices/name/{agent_id}
Publicada el · Actualizada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.1epss 0.2%
probabilidad de explotación
0.2%top 89% de las CVE
explotación observada
noninguna fuente lo reporta
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devices/name/{agent_id} endpoint. When an authenticated user renames a device, the new_name value is stored and later rendered in device listings or detail views without proper HTML sanitation. An attacker can inject malicious script into the device name, which is then executed in the browser context of users who view or interact with the affected device, potentially enabling session compromise and unauthorized actions as the victim.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Productos afectados
Advantech Co., Ltd. · WISE-DeviceOn ServerCVEs relacionadas — Advantech Co., Ltd. WISE-DeviceOn Server
En el mismo producto, de las más peligrosas a las menos.
CVE-2025-34256CRITICALAdvantech WISE-DeviceOn Server < 5.4 Hard-coded JWT Key Authentication BypassEPSS 0.7%CVE-2025-34259MEDIUMAdvantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devicemap/buildingEPSS 0.3%CVE-2025-34261MEDIUMAdvantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devicegroups/EPSS 0.3%CVE-2025-34257MEDIUMAdvantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via action/definedEPSS 0.3%CVE-2025-34260MEDIUMAdvantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via action/scheduleEPSS 0.3%CVE-2025-34266MEDIUMAdvantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via plugin-config/addins/menusEPSS 0.2%
Referencias
https://advcloudfiles.advantech.com/cms/2ca1b071-fd78-4d7f-8a2a-7b4537a95d19/Security%20Advisory%20PDF%20File/SECURITY-ADVISORY----DeviceOn-20251208-2.pdfhttps://docs.deviceon.advantech.com/docs/resource/https://www.vulncheck.com/advisories/advantech-wise-deviceon-server-authenticated-stored-xss-via-devices-name-agentid