CVE-2025-34256: Advantech WISE-DeviceOn Server < 5.4 Hard-coded JWT Key Authentication Bypass
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product uses a static HS512 HMAC secret for signing EIRMMToken JWTs across all installations. The server accepts forged JWTs that need only contain a valid email claim, allowing a remote unauthenticated attacker to generate arbitrary tokens and impersonate any DeviceOn account, including the root super admin. Successful exploitation permits full administrative control of the DeviceOn instance and can be leveraged to execute code on managed agents through DeviceOn’s remote management features.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34256?
CVE-2025-34256 is classified as a high severity vulnerability due to the potential for authentication bypass.
How do I fix CVE-2025-34256?
To mitigate CVE-2025-34256, upgrade Advantech WISE-DeviceOn Server to version 5.4 or later.
What is the impact of CVE-2025-34256?
CVE-2025-34256 allows attackers to forge JWTs, potentially accessing protected resources without proper authentication.
Which versions of Advantech WISE-DeviceOn Server are affected by CVE-2025-34256?
All versions of Advantech WISE-DeviceOn Server prior to 5.4 are vulnerable to CVE-2025-34256.
Is there a workaround for CVE-2025-34256 if I cannot upgrade?
No official workaround is provided for CVE-2025-34256; the recommended action is to upgrade to the latest version.