CVE-2025-34261: falha de média gravidade em Advantech Co., Ltd. WISE-DeviceOn Server
Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devicegroups/
Publicada em · Atualizada em
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 5.1epss 0.3%
probabilidade de exploração
0.3%top 84% das CVEs
exploração observada
nãonenhuma fonte reporta
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicegroups/ endpoint. When an authenticated user creates a device group, the name and description values are stored and later rendered in device group listings without proper HTML sanitation. An attacker can inject malicious script into either field, which is then executed in the browser context of users who view or interact with the affected device group, potentially enabling session compromise and unauthorized actions as the victim.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Produtos afetados
Advantech Co., Ltd. · WISE-DeviceOn ServerCVEs relacionadas — Advantech Co., Ltd. WISE-DeviceOn Server
No mesmo produto, das mais perigosas para as menos.
CVE-2025-34256CRITICALAdvantech WISE-DeviceOn Server < 5.4 Hard-coded JWT Key Authentication BypassEPSS 0.7%CVE-2025-34259MEDIUMAdvantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devicemap/buildingEPSS 0.3%CVE-2025-34257MEDIUMAdvantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via action/definedEPSS 0.3%CVE-2025-34260MEDIUMAdvantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via action/scheduleEPSS 0.3%CVE-2025-34266MEDIUMAdvantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via plugin-config/addins/menusEPSS 0.2%CVE-2025-34262MEDIUMAdvantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devices/name/{agent_id}EPSS 0.2%
Referências
https://advcloudfiles.advantech.com/cms/2ca1b071-fd78-4d7f-8a2a-7b4537a95d19/Security%20Advisory%20PDF%20File/SECURITY-ADVISORY----DeviceOn-20251208-2.pdfhttps://docs.deviceon.advantech.com/docs/resource/https://www.vulncheck.com/advisories/advantech-wise-deviceon-server-authenticated-stored-xss-via-devicegroups