CVE-2025-34265: Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via rule-engines

Published Dec 5, 2025
·
Updated

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/rule-engines endpoint. When an authenticated user creates or updates a rule for an agent, the rule fields min, max, and unit are stored and later rendered in rule listings or detail views without proper HTML sanitation. An attacker can inject malicious script into one or more of these fields, which is then executed in the browser context of users who view or interact with the affected rule, potentially enabling session compromise and unauthorized actions as the victim.

Affected Software

2 affected components
Advantech WISE-DeviceOn Server<5.4
Advantech WISE-DeviceOn Server<5.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Advantech WISE-DeviceOn Server to a version that resolves this vulnerability.

    Fixed in 5.4
  2. Configuration

    Ensure stored XSS protections are applied to the rendered rule fields min, max, and unit in rule listings and detail views (proper HTML sanitization/escaping) so injected scripts are not executed in user browsers.

    WISE-DeviceOn Server (/rmm/v1/rule-engines endpoint) HTML sanitization/escaping for stored rule fields = enabled
  3. Compensating control

    Limit access to the /rmm/v1/rule-engines endpoint so only authorized users/agents can create or update rules, reducing the ability to inject malicious content.

Event History

Dec 5, 2025
CVE Published
via MITRE·05:18 PM
Data Sourced
via MITRE·05:18 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-34265?

CVE-2025-34265 is classified as a medium severity stored cross-site scripting (XSS) vulnerability.

2

How do I fix CVE-2025-34265?

To fix CVE-2025-34265, upgrade the Advantech WISE-DeviceOn Server to version 5.4 or later.

3

Who is affected by CVE-2025-34265?

CVE-2025-34265 affects users of Advantech WISE-DeviceOn Server versions prior to 5.4.

4

What are the potential impacts of CVE-2025-34265?

The potential impacts of CVE-2025-34265 include unauthorized execution of scripts in the context of the user’s session.

5

Can CVE-2025-34265 be exploited remotely?

CVE-2025-34265 requires authentication, so it can only be exploited by authenticated users with access to the system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203