Stored XSS Vulnerability in Advantech WISE-DeviceOn Server Software
CVE-2025-34258
5.1MEDIUM
Key Information:
- Vendor
Advantech Co., Ltd.
- Status
- Vendor
- CVE Published:
- 5 December 2025
What is CVE-2025-34258?
Advantech WISE-DeviceOn Server prior to version 5.4 displays a stored cross-site scripting (XSS) vulnerability at the /rmm/v1/devicemap/plan endpoint. An authenticated user can add an area with a name that, due to a lack of proper HTML sanitization, can contain malicious scripts. This vulnerability allows attackers to inject scripts that execute in the context of users who view the affected map entry, facilitating session hijacking and unauthorized user actions.
Affected Version(s)
WISE-DeviceOn Server 0 < 5.4
