Stored Cross-Site Scripting Vulnerability in Advantech WISE-DeviceOn Server
CVE-2025-34266
5.1MEDIUM
Key Information:
- Vendor
Advantech Co., Ltd.
- Status
- Vendor
- CVE Published:
- 5 December 2025
What is CVE-2025-34266?
The Advantech WISE-DeviceOn Server before version 5.4 has a stored cross-site scripting (XSS) vulnerability that affects the /rmm/v1/plugin-config/addins/menus endpoint. This flaw allows an authenticated user to inject malicious scripts into the AddIns menu configuration. As these values are stored and rendered without proper HTML sanitization, an attacker can execute scripts in the context of the user's browser, leading to potential session compromise and unauthorized actions. It is crucial for users to upgrade to the latest version to mitigate this security risk.
Affected Version(s)
WISE-DeviceOn Server 0 < 5.4
