CVE 10 CRITICAL

Advantech WISE-DeviceOn Server < 5.4 Hard-coded JWT Key Authentication Bypass_CVE-2025-34256

10 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Description

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product uses a static HS512 HMAC secret for signing EIRMMToken JWTs across all installations. The server accepts forged JWTs that need only contain a valid email claim, allowing a remote unauthenticated attacker to generate arbitrary tokens and impersonate any DeviceOn account, including the root super admin. Successful exploitation permits full administrative control of the DeviceOn instance and can be leveraged to execute code on managed agents through DeviceOn’s remote management features.

AI Analysis

Hard-coded cryptographic key vulnerability allowing remote unauthenticated attackers to generate arbitrary tokens and impersonate any DeviceOn account.

Basic Information

ID CVE-2025-34256
Source VulnCheck
Published Dec 5, 2025 at 17:18

Affected Product

Vendor Advantech Co., Ltd.
Product WISE-DeviceOn Server
Affected Versions Advantech Co., Ltd. WISE-DeviceOn Server 0

CWE Classification

AI Assessment

AI Score 10 / 10
AI Severity Critical
Vendor Advantech
Product WISE-DeviceOn Server
Version < 5.4

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.