PT-2025-48040 · Ilevia · Ilevia Eve X1 Server Firmware+1

See857

·

Published

2025-11-25

·

Updated

2025-12-30

·

CVE-2025-60739

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ilevia EVE X1 Server Firmware versions prior to v4.7.18.0.eden Ilevia EVE Logic versions prior to v6.00 - 2025 07 21
Description A Cross Site Request Forgery (CSRF) issue exists in the /bh web backend component. This allows a remote attacker to potentially execute arbitrary code.
Recommendations Update Ilevia EVE X1 Server Firmware to version v4.7.18.0.eden or later. Update Ilevia EVE Logic to version v6.00 - 2025 07 21 or later.

Exploit

Fix

Information Disclosure

XSS

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-60739

Affected Products

Ilevia Eve Logic
Ilevia Eve X1 Server Firmware