Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product uses a static HS512 HMAC secret for signing EIRMMToken JWTs across all installations. The server accepts forged JWTs that need only contain a valid email claim, allowing a remote unauthenticated attacker to generate arbitrary tokens and impersonate any DeviceOn account, including the root super admin. Successful exploitation permits full administrative control of the DeviceOn instance and can be leveraged to execute code on managed agents through DeviceOn’s remote management features.
History

Thu, 11 Dec 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Advantech wise-deviceon Server
CPEs cpe:2.3:a:advantech:wise-deviceon_server:*:*:*:*:*:*:*:*
Vendors & Products Advantech wise-deviceon Server
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Tue, 09 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 05 Dec 2025 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Advantech
Advantech wise-deviceon
Vendors & Products Advantech
Advantech wise-deviceon

Fri, 05 Dec 2025 17:30:00 +0000

Type Values Removed Values Added
Description Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product uses a static HS512 HMAC secret for signing EIRMMToken JWTs across all installations. The server accepts forged JWTs that need only contain a valid email claim, allowing a remote unauthenticated attacker to generate arbitrary tokens and impersonate any DeviceOn account, including the root super admin. Successful exploitation permits full administrative control of the DeviceOn instance and can be leveraged to execute code on managed agents through DeviceOn’s remote management features.
Title Advantech WISE-DeviceOn Server < 5.4 Hard-coded JWT Key Authentication Bypass
Weaknesses CWE-321
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-12-05T17:18:31.747Z

Updated: 2025-12-09T16:41:39.876Z

Reserved: 2025-04-15T19:15:22.578Z

Link: CVE-2025-34256

cve-icon Vulnrichment

Updated: 2025-12-09T16:41:37.164Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-05T18:15:55.053

Modified: 2025-12-11T18:13:32.750

Link: CVE-2025-34256

cve-icon Redhat

No data.