PT-2025-38076 · Ilevia · Ilevia Eve X1/X5 Server

Gjoko Krstic

·

Published

2025-09-16

·

Updated

2026-05-26

·

CVE-2025-34186

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ilevia EVE X1/X5 Server versions prior to 4.7.18.0.eden
Description The Ilevia EVE X1/X5 Server authentication mechanism has a flaw where unsanitized input is passed to a system() call during authentication. This allows attackers to inject special characters and manipulate command parsing. Because the binary interprets non-zero exit codes as successful authentication, remote attackers can bypass authentication and gain full access to the system.
Recommendations Update Ilevia EVE X1/X5 Server to version 4.7.18.0.eden or later. As a temporary workaround, restrict access to the authentication module to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-34186

Affected Products

Ilevia Eve X1/X5 Server