PT-2025-47580 · Ilevia · Ilevia Eve X1 Server Firmware+1
Published
2025-11-20
·
Updated
2025-11-20
·
CVE-2025-60738
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ilevia EVE X1 Server Firmware versions v4.7.18.0.eden and before
Ilevia EVE Logic versions v6.00 - 2025 07 21 and before
Description
A flaw exists that could allow a remote attacker to execute arbitrary code. This is due to insufficient input validation on IP parameters within the
ping.php component.Recommendations
Update Ilevia EVE X1 Server Firmware to a version later than v4.7.18.0.eden.
Update Ilevia EVE Logic to a version later than v6.00 - 2025 07 21.
Exploit
Fix
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ilevia Eve Logic
Ilevia Eve X1 Server Firmware