CVE-2025-34266: fallo de gravedad media en Advantech Co., Ltd. WISE-DeviceOn Server
Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via plugin-config/addins/menus
Publicada el · Actualizada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.1epss 0.2%
probabilidad de explotación
0.2%top 89% de las CVE
explotación observada
noninguna fuente lo reporta
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/plugin-config/addins/menus endpoint. When an authenticated user adds or edits an AddIns menu entry, the label and path values are stored in plugin configuration data and later rendered in the AddIns UI without proper HTML sanitation. An attacker can inject malicious script into either field, which is then executed in the browser context of users who view or interact with the affected AddIns entry, potentially enabling session compromise and unauthorized actions as the victim.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Productos afectados
Advantech Co., Ltd. · WISE-DeviceOn ServerCVEs relacionadas — Advantech Co., Ltd. WISE-DeviceOn Server
En el mismo producto, de las más peligrosas a las menos.
CVE-2025-34256CRITICALAdvantech WISE-DeviceOn Server < 5.4 Hard-coded JWT Key Authentication BypassEPSS 0.7%CVE-2025-34259MEDIUMAdvantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devicemap/buildingEPSS 0.3%CVE-2025-34261MEDIUMAdvantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devicegroups/EPSS 0.3%CVE-2025-34257MEDIUMAdvantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via action/definedEPSS 0.3%CVE-2025-34260MEDIUMAdvantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via action/scheduleEPSS 0.3%CVE-2025-34262MEDIUMAdvantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devices/name/{agent_id}EPSS 0.2%
Referencias
https://advcloudfiles.advantech.com/cms/2ca1b071-fd78-4d7f-8a2a-7b4537a95d19/Security%20Advisory%20PDF%20File/SECURITY-ADVISORY----DeviceOn-20251208-2.pdfhttps://docs.deviceon.advantech.com/docs/resource/https://www.vulncheck.com/advisories/advantech-wise-deviceon-server-authenticated-stored-xss-via-pluginconfig-addins-menus