PT-2025-47580 · Ilevia · Ilevia Eve X1 Server Firmware+1

Published

2025-11-20

·

Updated

2025-11-20

·

CVE-2025-60738

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ilevia EVE X1 Server Firmware versions v4.7.18.0.eden and before Ilevia EVE Logic versions v6.00 - 2025 07 21 and before
Description A flaw exists that could allow a remote attacker to execute arbitrary code. This is due to insufficient input validation on IP parameters within the ping.php component.
Recommendations Update Ilevia EVE X1 Server Firmware to a version later than v4.7.18.0.eden. Update Ilevia EVE Logic to a version later than v6.00 - 2025 07 21.

Exploit

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-60738

Affected Products

Ilevia Eve Logic
Ilevia Eve X1 Server Firmware