Stored Cross-Site Scripting Vulnerability in Advantech WISE-DeviceOn Server
CVE-2025-34263
5.1MEDIUM
Key Information:
- Vendor
Advantech Co., Ltd.
- Status
- Vendor
- CVE Published:
- 5 December 2025
What is CVE-2025-34263?
The Advantech WISE-DeviceOn Server prior to version 5.4 is susceptible to a stored cross-site scripting (XSS) vulnerability found in the /rmm/v1/plugin-config/dashboards/menus endpoint. An authenticated user can exploit this flaw while adding or modifying dashboard entries, resulting in malicious scripts being executed in the browsers of users interacting with the affected dashboards. This vulnerability arises from the inadequate HTML sanitization of stored data, leading to potential session hijacking and unauthorized actions by attackers.
Affected Version(s)
WISE-DeviceOn Server 0 < 5.4
