Skip to main content

Vendor/product archive

advantech / wise-deviceon_server CVEs

Beta · best-effort

11 CVEs tagged to advantech / wise-deviceon_server1 Critical, 0 High, 10 Medium, 0 Low, 0 Unrated.

CVE-2025-34266

Published Dec 5, 2025

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/plugin-config/addins/menus endpoint. When an authenti…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34265

Published Dec 5, 2025

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/rule-engines endpoint. When an authenticated user cre…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34264

Published Dec 5, 2025

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/dog/{agentId} endpoint. When an authenticated user ad…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34263

Published Dec 5, 2025

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/plugin-config/dashboards/menus endpoint. When an auth…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34262

Published Dec 5, 2025

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devices/name/{agent_id} endpoint. When an authenticat…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34261

Published Dec 5, 2025

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicegroups/ endpoint. When an authenticated user cr…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34260

Published Dec 5, 2025

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/schedule endpoint. When an authenticated user…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34259

Published Dec 5, 2025

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/building endpoint. When an authenticated us…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34258

Published Dec 5, 2025

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/plan endpoint. When an authenticated user a…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34257

Published Dec 5, 2025

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/defined endpoint. When an authenticated user c…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34256

Published Dec 5, 2025

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product uses a static HS512 HMAC secret for signing EIRMMToken JWTs…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1