Stored Cross-Site Scripting Vulnerability in Advantech WISE-DeviceOn Server
CVE-2025-34263
Key Information:
- Vendor
Advantech Co., Ltd.
- Status
- Vendor
- CVE Published:
- 5 December 2025
What is CVE-2025-34263?
The Advantech WISE-DeviceOn Server prior to version 5.4 is susceptible to a stored cross-site scripting (XSS) vulnerability found in the /rmm/v1/plugin-config/dashboards/menus endpoint. An authenticated user can exploit this flaw while adding or modifying dashboard entries, resulting in malicious scripts being executed in the browsers of users interacting with the affected dashboards. This vulnerability arises from the inadequate HTML sanitization of stored data, leading to potential session hijacking and unauthorized actions by attackers.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WISE-DeviceOn Server 0 < 5.4
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
