Stored Cross-Site Scripting Vulnerability in Advantech WISE-DeviceOn Server
CVE-2025-34266
Key Information:
- Vendor
Advantech Co., Ltd.
- Status
- Vendor
- CVE Published:
- 5 December 2025
What is CVE-2025-34266?
The Advantech WISE-DeviceOn Server before version 5.4 has a stored cross-site scripting (XSS) vulnerability that affects the /rmm/v1/plugin-config/addins/menus endpoint. This flaw allows an authenticated user to inject malicious scripts into the AddIns menu configuration. As these values are stored and rendered without proper HTML sanitization, an attacker can execute scripts in the context of the user's browser, leading to potential session compromise and unauthorized actions. It is crucial for users to upgrade to the latest version to mitigate this security risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WISE-DeviceOn Server 0 < 5.4
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
