CVE-2025-34264: Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via dog/{agentId}
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/dog/{agentId} endpoint. When an authenticated user adds or edits Software Watchdog process rules for an agent, the monitored process name is stored in the settings array and later rendered in the Software Watchdog UI without proper HTML sanitation. An attacker can inject malicious script into the process name, which is then executed in the browser context of users who view or interact with the affected rules, potentially enabling session compromise and unauthorized actions as the victim.
Security readout for executives and security teams
Plain-English summary
An authenticated user can save a malicious process name in WISE-DeviceOn Server. When another user opens the affected Software Watchdog rules, browser script may run with that user’s privileges, risking session compromise and unauthorized actions. The supplied description identifies versions before 5.4 as vulnerable.
Executive priority
Prioritize remediation on externally reachable or broadly administered management servers. Although rated moderate, successful abuse could act through a more privileged viewer’s session. Upgrade promptly through normal change control, restrict rule-editing access, and investigate suspicious watchdog entries. Emergency treatment is not supported by the supplied exploitation evidence.
Technical view
CVE-2025-34264 is stored cross-site scripting in /rmm/v1/dog/{agentId}. Software Watchdog process names enter the settings array without adequate HTML sanitation and are later rendered by the management UI. Exploitation requires low privileges and passive victim interaction. CVSS 4.0 is 5.1, with limited confidentiality and integrity impacts across browser contexts.
Likely exposure
Exposure is likely where WISE-DeviceOn Server earlier than 5.4 is deployed and untrusted or compromised authenticated accounts can manage Software Watchdog rules. A privileged user must subsequently view or interact with the affected rule. The structured affected-version metadata is inconsistent, so inventory confirmation against vendor guidance is important.
Exploitation context
The source bundle does not establish active exploitation, and the CVE is not identified as being in KEV. Exploitation requires authentication, the ability to add or edit watchdog process rules, and a user opening the stored rule. Internet exposure could increase access opportunities but is not required by the described attack path.
Researcher notes
The key boundary is unsafe persistence and later HTML rendering of settings-array process names. Assessment should trace server-side validation, output encoding, UI rendering, authorization, and affected-session scope. The bundle says versions before 5.4 are affected, but its structured version entry lists “0” with default unaffected; consult the vendor advisory to resolve this discrepancy.
Mitigation direction
Upgrade WISE-DeviceOn Server to version 5.4 or later, following the vendor advisory.
Restrict Software Watchdog rule editing to trusted, necessary accounts.
Review existing process names for unexpected HTML or script-like content.
Limit management-interface access using network and identity controls.
Invalidate potentially exposed sessions if suspicious stored content is discovered.
Validation and detection
Inventory WISE-DeviceOn Server instances and record their exact versions.
Confirm every instance runs version 5.4 or later.
Review permissions for adding or editing Software Watchdog rules.
Inspect stored watchdog process names for unexpected markup without rendering it.
Check audit and authentication records for suspicious rule changes or session activity.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-79: User-session and phishing behavior lookup
Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-79 · source CWE mapping
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.