Medium severity5.4NVD Advisory· Published Dec 5, 2025· Updated Sep 25, 2026
CVE-2025-34257
CVE-2025-34257
Description
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/defined endpoint. When an authenticated user creates a task, the defined_name value is stored and later rendered in the Overview page without HTML sanitization. An attacker can inject malicious script into defined_name, which is then executed in the browser context of users who view the affected task, potentially enabling session compromise and unauthorized actions as the victim.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: <5.4
- Advantech Co., Ltd./WISE-DeviceOn Serverv5Range: 0
<5.4+ 1 more
- (no CPE)range: <5.4
- cpe:2.3:a:advantech:wise-deviceon_server:*:*:*:*:*:*:*:*range: <5.4
Patches
Vulnerability mechanics
References
3- www.vulncheck.com/advisories/advantech-wise-deviceon-server-authenticated-stored-xss-via-action-definednvdThird Party Advisory
- docs.deviceon.advantech.com/docs/resource/nvdProduct
- advcloudfiles.advantech.com/cms/2ca1b071-fd78-4d7f-8a2a-7b4537a95d19/Security%20Advisory%20PDF%20File/SECURITY-ADVISORY----DeviceOn-20251208-2.pdfnvd
News mentions
0No linked articles in our index yet.