PT-2025-42505 · Ilevia · Ilevia Eve X1 Server

Gjoko Krstic

·

Published

2025-10-16

·

Updated

2025-10-16

·

CVE-2025-34517

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ilevia EVE X1 Server firmware versions through 4.7.18.0.eden
Description The software contains an absolute path traversal flaw in the get file content.php component. This allows an attacker to read arbitrary files. The vendor has declined to provide a service for this issue and recommends not exposing port 8080 to the internet.
Recommendations Do not expose port 8080 to the internet.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-34517

Affected Products

Ilevia Eve X1 Server