PT-2025-38076 · Ilevia · Ilevia Eve X1/X5 Server
Gjoko Krstic
·
Published
2025-09-16
·
Updated
2026-05-26
·
CVE-2025-34186
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ilevia EVE X1/X5 Server versions prior to 4.7.18.0.eden
Description
The Ilevia EVE X1/X5 Server authentication mechanism has a flaw where unsanitized input is passed to a
system() call during authentication. This allows attackers to inject special characters and manipulate command parsing. Because the binary interprets non-zero exit codes as successful authentication, remote attackers can bypass authentication and gain full access to the system.Recommendations
Update Ilevia EVE X1/X5 Server to version 4.7.18.0.eden or later.
As a temporary workaround, restrict access to the authentication module to minimize the risk of exploitation.
Exploit
Fix
OS Command Injection
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ilevia Eve X1/X5 Server