← Vulnerability feed

Vulnerability record · CVE-2025-34514 · published 16 October 2025

CVE-2025-34514: Ilevia eve x1 server firmware os command injection vulnerability

IIlevia · Eve X1 Server Firmware

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection vulnerabilities in multiple web-accessible PHP scripts that call exec() and allow an authenticated attacker to execute arbitrary commands. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.

8.7 CVSS 4.0 High EPSS 2.0% · top 20.2% CWE-78 · OS command injection
8.7CVSS 4.0 base score
2.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection vulnerabilities in multiple web-accessible PHP scripts that call exec() and allow an authenticated attacker to execute arbitrary commands. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-34514 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-60738Ilevia eve x1 server firmware os command injection vulnerabilityAn issue in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before Logic Version v6.00 - 2025_07_21 and before allows a remote attacker to e…EPSS 1.0%9.6CVE-2025-60739Ilevia eve x1 server firmware cross-site scripting vulnerabilityCross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before, Logic Version v6.00 - 2025_07_21 …EPSS 0.33%9.3CVE-2025-34516Ilevia eve x1 server firmware vulnerabilityIlevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unauthenticated attacker to …EPSS 0.59%9.3CVE-2025-34513Ilevia eve x1 server firmware os command injection vulnerabilityIlevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_csv.php that allows an unauth…EPSS 7.6%9.3CVE-2025-34515Ilevia eve x1 server firmware execution with unnecessary privileges vulnerabilityIlevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in sync_project.sh that allows …EPSS 8.0%9.3CVE-2025-34183Ilevia eve x1 server firmware sensitive information in log file vulnerabilityIlevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attacke…EPSS 0.70%9.3CVE-2025-34184Ilevia eve x1 server firmware os command injection vulnerabilityIlevia EVE X1 Server version ≤ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax/php/login.php script. Remote…EPSS 2.7%9.3CVE-2025-34186Ilevia eve x1 server firmware os command injection vulnerabilityIlevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() c…EPSS 0.87%

Source: NIST National Vulnerability Database (record CVE-2025-34514), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.