📦 Wise Deviceon Server

by Advantech

🔍 What is Wise Deviceon Server?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-34256

CRITICAL CVSS 9.8 Dec 5, 2025

This vulnerability allows remote unauthenticated attackers to forge JWT tokens using a hard-coded cryptographic key present in all Advantech WISE-DeviceOn Server installations. Attackers can impersona...

CVE-2025-34263

MEDIUM CVSS 5.4 Dec 5, 2025

Advantech WISE-DeviceOn Server versions before 5.4 contain a stored cross-site scripting vulnerability in the dashboard menu configuration endpoint. Authenticated attackers can inject malicious script...

CVE-2025-34264

MEDIUM CVSS 5.4 Dec 5, 2025

Advantech WISE-DeviceOn Server versions before 5.4 contain a stored cross-site scripting vulnerability in the Software Watchdog interface. Authenticated attackers can inject malicious scripts into pro...

CVE-2025-34265

MEDIUM CVSS 5.4 Dec 5, 2025

This stored XSS vulnerability in Advantech WISE-DeviceOn Server allows authenticated attackers to inject malicious scripts into rule engine fields. When other users view or interact with these rules, ...

CVE-2025-34266

MEDIUM CVSS 5.4 Dec 5, 2025

This is an authenticated stored cross-site scripting (XSS) vulnerability in Advantech WISE-DeviceOn Server. An authenticated attacker can inject malicious scripts into AddIns menu entries, which execu...

CVE-2025-34257

MEDIUM CVSS 5.4 Dec 5, 2025

This stored XSS vulnerability in Advantech WISE-DeviceOn Server allows authenticated attackers to inject malicious scripts into task names that execute when other users view affected tasks. The vulner...

CVE-2025-34258

MEDIUM CVSS 5.4 Dec 5, 2025

This stored XSS vulnerability in Advantech WISE-DeviceOn Server allows authenticated attackers to inject malicious scripts into map area names. When other users view or interact with the affected map ...

CVE-2025-34259

MEDIUM CVSS 5.4 Dec 5, 2025

This stored XSS vulnerability in Advantech WISE-DeviceOn Server allows authenticated attackers to inject malicious scripts into map entry names. When other users view these entries, the scripts execut...

CVE-2025-34260

MEDIUM CVSS 5.4 Dec 5, 2025

Advantech WISE-DeviceOn Server versions before 5.4 contain a stored cross-site scripting vulnerability in the schedule management endpoint. Authenticated attackers can inject malicious scripts into sc...

CVE-2025-34261

MEDIUM CVSS 5.4 Dec 5, 2025

This stored XSS vulnerability in Advantech WISE-DeviceOn Server allows authenticated attackers to inject malicious scripts into device group names and descriptions. When other users view these device ...

CVE-2025-34262

MEDIUM CVSS 5.4 Dec 5, 2025

This stored XSS vulnerability in Advantech WISE-DeviceOn Server allows authenticated attackers to inject malicious scripts into device names. When other users view or interact with these devices, the ...