LiveActive security incident?Get immediate response
CVE Record

CVE-2025-34264: Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via dog/{agentId}

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/dog/{agentId} endpoint. When an authenticated user adds or edits Software Watchdog process rules for an agent, the monitored process name is stored in the settings array and later rendered in the Software Watchdog UI without proper HTML sanitation. An attacker can inject malicious script into the process name, which is then executed in the browser context of users who view or interact with the affected rules, potentially enabling session compromise and unauthorized actions as the victim.

MediumCVSS 5.1Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

An authenticated user can save a malicious process name in WISE-DeviceOn Server. When another user opens the affected Software Watchdog rules, browser script may run with that user’s privileges, risking session compromise and unauthorized actions. The supplied description identifies versions before 5.4 as vulnerable.

Executive priority

Prioritize remediation on externally reachable or broadly administered management servers. Although rated moderate, successful abuse could act through a more privileged viewer’s session. Upgrade promptly through normal change control, restrict rule-editing access, and investigate suspicious watchdog entries. Emergency treatment is not supported by the supplied exploitation evidence.

Technical view

CVE-2025-34264 is stored cross-site scripting in /rmm/v1/dog/{agentId}. Software Watchdog process names enter the settings array without adequate HTML sanitation and are later rendered by the management UI. Exploitation requires low privileges and passive victim interaction. CVSS 4.0 is 5.1, with limited confidentiality and integrity impacts across browser contexts.

Likely exposure

Exposure is likely where WISE-DeviceOn Server earlier than 5.4 is deployed and untrusted or compromised authenticated accounts can manage Software Watchdog rules. A privileged user must subsequently view or interact with the affected rule. The structured affected-version metadata is inconsistent, so inventory confirmation against vendor guidance is important.

Exploitation context

The source bundle does not establish active exploitation, and the CVE is not identified as being in KEV. Exploitation requires authentication, the ability to add or edit watchdog process rules, and a user opening the stored rule. Internet exposure could increase access opportunities but is not required by the described attack path.

Researcher notes

The key boundary is unsafe persistence and later HTML rendering of settings-array process names. Assessment should trace server-side validation, output encoding, UI rendering, authorization, and affected-session scope. The bundle says versions before 5.4 are affected, but its structured version entry lists “0” with default unaffected; consult the vendor advisory to resolve this discrepancy.

Mitigation direction

  • Upgrade WISE-DeviceOn Server to version 5.4 or later, following the vendor advisory.
  • Restrict Software Watchdog rule editing to trusted, necessary accounts.
  • Review existing process names for unexpected HTML or script-like content.
  • Limit management-interface access using network and identity controls.
  • Invalidate potentially exposed sessions if suspicious stored content is discovered.

Validation and detection

  • Inventory WISE-DeviceOn Server instances and record their exact versions.
  • Confirm every instance runs version 5.4 or later.
  • Review permissions for adding or editing Software Watchdog rules.
  • Inspect stored watchdog process names for unexpected markup without rendering it.
  • Check audit and authentication records for suspicious rule changes or session activity.
Prepared
Confidence
high
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-79: User-session and phishing behavior lookup

Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2025-34264 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
5.1 (4.0)
Known Exploited
No
Published

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
1ADP providers
4Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
5.1CVSS 4.0MediumCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:NVulnCheck

Vulnerability scoring details

Base CVSS 4.0 score

5.1Medium
CVSS 4.0 vector shape for CVE-2025-34264Attack VectorAttack ComplexityAttack RequirementsPrivileges RequiredUser InteractionVS ConfidentialityVS IntegrityVS AvailabilitySS ConfidentialitySS IntegritySS Availability

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Attack Requirements
NonePresent
Privileges Required
NoneLowHigh
User Interaction
NonePassiveActive
VS Confidentiality
HighLowNone
VS Integrity
HighLowNone
VS Availability
HighLowNone
SS Confidentiality
HighLowNone
SS Integrity
HighLowNone
SS Availability
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Advantech Co., Ltd.WISE-DeviceOn Server0unaffected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-79 · source CWE mapping

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.