CVE-2025-64302: Advantech DeviceOn/iEdge Cross-site Scripting
Insufficient input sanitization in the dashboard label or path can allow an attacker to trigger a device error causing information disclosure or data manipulation.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64302?
CVE-2025-64302 has a high severity rating due to the potential for information disclosure and data manipulation.
How do I fix CVE-2025-64302?
To fix CVE-2025-64302, update Advantech DeviceOn/iEdge to version 2.0.3 or later, which addresses the insufficient input sanitization issue.
What are the main risks associated with CVE-2025-64302?
The main risks associated with CVE-2025-64302 include device errors that can lead to unauthorized information disclosure and the possibility of data manipulation.
Is CVE-2025-64302 easily exploitable?
Yes, CVE-2025-64302 is considered easily exploitable due to the insufficient input sanitization in the affected software.
Which versions of Advantech DeviceOn/iEdge are affected by CVE-2025-64302?
Advantech DeviceOn/iEdge versions 2.0.2 and prior are affected by CVE-2025-64302.