Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 17 Dec 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 17 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 11 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Advantech wise-deviceon Server
|
|
| CPEs | cpe:2.3:a:advantech:wise-deviceon_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Advantech wise-deviceon Server
|
|
| Metrics |
cvssV3_1
|
Tue, 09 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Dec 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Advantech
Advantech wise-deviceon |
|
| Vendors & Products |
Advantech
Advantech wise-deviceon |
Fri, 05 Dec 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/defined endpoint. When an authenticated user creates a task, the defined_name value is stored and later rendered in the Overview page without HTML sanitization. An attacker can inject malicious script into defined_name, which is then executed in the browser context of users who view the affected task, potentially enabling session compromise and unauthorized actions as the victim. | |
| Title | Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via action/defined | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-14T02:08:00.816Z
Reserved: 2025-04-15T19:15:22.578Z
Link: CVE-2025-34257
Updated: 2025-12-09T20:42:59.971Z
Status : Modified
Published: 2025-12-05T18:15:55.220
Modified: 2025-12-17T17:15:48.980
Link: CVE-2025-34257
No data.
OpenCVE Enrichment
Updated: 2025-12-05T20:56:09Z