Advantech WISE-DeviceOn 5.4- HS512 HMAC Key Hard-coded JWT Forge
CVE-2025-34256 Published on December 5, 2025

Advantech WISE-DeviceOn Server < 5.4 Hard-coded JWT Key Authentication Bypass
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product uses a static HS512 HMAC secret for signing EIRMMToken JWTs across all installations. The server accepts forged JWTs that need only contain a valid email claim, allowing a remote unauthenticated attacker to generate arbitrary tokens and impersonate any DeviceOn account, including the root super admin. Successful exploitation permits full administrative control of the DeviceOn instance and can be leveraged to execute code on managed agents through DeviceOns remote management features.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2025-34256 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. An automatable proof of concept (POC) exploit exists. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE

Weakness Type

Use of Hard-coded Cryptographic Key

The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.


Products Associated with CVE-2025-34256

Want to know whenever a new CVE is published for Advantech Wise Deviceon Server? stack.watch will email you.

 

Affected Versions

Advantech Co., Ltd. WISE-DeviceOn Server:

Exploit Probability

EPSS
0.68%
Percentile
49.03%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.