10
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Description
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product uses a static HS512 HMAC secret for signing EIRMMToken JWTs across all installations. The server accepts forged JWTs that need only contain a valid email claim, allowing a remote unauthenticated attacker to generate arbitrary tokens and impersonate any DeviceOn account, including the root super admin. Successful exploitation permits full administrative control of the DeviceOn instance and can be leveraged to execute code on managed agents through DeviceOnβs remote management features.
AI Analysis
Hard-coded cryptographic key vulnerability allowing remote unauthenticated attackers to generate arbitrary tokens and impersonate any DeviceOn account.
Basic Information
ID
CVE-2025-34256
Source
VulnCheck
Published
Dec 5, 2025 at 17:18
Affected Product
Vendor
Advantech Co., Ltd.
Product
WISE-DeviceOn Server
Affected Versions
Advantech Co., Ltd. WISE-DeviceOn Server 0
CWE Classification
AI Assessment
AI Score
10 / 10
AI Severity
Critical
Vendor
Advantech
Product
WISE-DeviceOn Server
Version
< 5.4