CVE-2025-34258: Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devicemap/plan
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/plan endpoint. When an authenticated user adds an area to a map entry, the name parameter is stored and later rendered in the map list without HTML sanitization. An attacker can inject malicious script into the area name, which is then executed in the browser context of users who view or interact with the affected map entry, potentially enabling session compromise and unauthorized actions as the victim.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Advantech WISE-DeviceOn Serverto a version that resolves this vulnerability.Fixed in 5.4 - Compensating control
Mitigate by preventing access to the affected WISE-DeviceOn Server map functionality/endpoint (/rmm/v1/devicemap/plan) from untrusted users until the server is upgraded to 5.4.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34258?
CVE-2025-34258 is classified as a medium severity stored cross-site scripting (XSS) vulnerability.
How do I fix CVE-2025-34258?
To fix CVE-2025-34258, upgrade to Advantech WISE-DeviceOn Server version 5.4 or later.
What components are affected by CVE-2025-34258?
CVE-2025-34258 affects all versions of Advantech WISE-DeviceOn Server prior to 5.4.
What is the impact of CVE-2025-34258?
The impact of CVE-2025-34258 allows an authenticated user to execute arbitrary JavaScript in the context of other users accessing the vulnerable page.
Who is affected by CVE-2025-34258?
Users of Advantech WISE-DeviceOn Server prior to version 5.4 are affected by CVE-2025-34258.