PT-2025-42502 · Ilevia · Ilevia Eve X1 Server

Gjoko Krstic

·

Published

2025-10-16

·

Updated

2025-10-23

·

CVE-2025-34514

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ilevia EVE X1 Server firmware versions through 4.7.18.0.eden
Description The software contains authenticated OS command injection flaws in several web-accessible PHP scripts. These scripts utilize the exec() function, enabling a verified attacker to run arbitrary commands. The vendor has chosen not to address this issue and advises against exposing port 8080 to the public internet.
Recommendations Do not expose port 8080 to the internet.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-34514

Affected Products

Ilevia Eve X1 Server