CVE-2025-34256CRITICAL 9.8EPSS p43.7%

CVE-2025-34256CVE-2025-34256

Description

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product uses a static HS512 HMAC secret for signing EIRMMToken JWTs across all installations. The server accepts forged JWTs that need only contain a valid email claim, allowing a remote unauthenticated attacker to generate arbitrary tokens and impersonate any DeviceOn account, including the root super admin. Successful exploitation permits full administrative control of the DeviceOn instance and can be leveraged to execute code on managed agents through DeviceOn’s remote management features.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.59% probability of exploitation · percentile 43.7% · 2026-06-19T12:03:05Z
Published2025-12-05
Last modified2026-04-15

Underlying weaknesses· 1

CWE-321

References

  1. https://advcloudfiles.advantech.com/cms/2ca1b071-fd78-4d7f-8a2a-7b4537a95d19/Security%20Advisory%20PDF%20File/SECURITY-ADVISORY----DeviceOn-20251208-2.pdf
  2. https://docs.deviceon.advantech.com/docs/resource/
  3. https://pellera.com/blog/advantech-wise-deviceon-cve-2025-34256-vulnerability/
  4. https://www.vulncheck.com/advisories/advantech-wise-deviceon-server-hardcoded-jwt-key-authentication-bypass

1

TypeTargetConfidenceTier
WeaknessUse of Hard-coded Cryptographic Keycwe-3210%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-54807
CVE
CVE-2025-41702
CVE
CVE-2025-41672
CVE
CVE-2025-56577
CVE
CVE-2025-1242
CVE
CVE-2025-51606
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.