← Vulnerability feed

Vulnerability record · CVE-2025-34515 · published 16 October 2025

CVE-2025-34515: Ilevia eve x1 server firmware execution with unnecessary privileges vulnerability

IIlevia · Eve X1 Server Firmware

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in sync_project.sh that allows an attacker to escalate privileges to root. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.

9.3 CVSS 4.0 Critical EPSS 8.0% · top 5.4% CWE-250 · Execution with unnecessary privileges
9.3CVSS 4.0 base score
8.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in sync_project.sh that allows an attacker to escalate privileges to root. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-34515 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-60738Ilevia eve x1 server firmware os command injection vulnerabilityAn issue in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before Logic Version v6.00 - 2025_07_21 and before allows a remote attacker to e…EPSS 1.0%9.6CVE-2025-60739Ilevia eve x1 server firmware cross-site scripting vulnerabilityCross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before, Logic Version v6.00 - 2025_07_21 …EPSS 0.33%9.3CVE-2025-34516Ilevia eve x1 server firmware vulnerabilityIlevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unauthenticated attacker to …EPSS 0.59%9.3CVE-2025-34513Ilevia eve x1 server firmware os command injection vulnerabilityIlevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_csv.php that allows an unauth…EPSS 7.6%9.3CVE-2025-34183Ilevia eve x1 server firmware sensitive information in log file vulnerabilityIlevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attacke…EPSS 0.70%9.3CVE-2025-34184Ilevia eve x1 server firmware os command injection vulnerabilityIlevia EVE X1 Server version ≤ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax/php/login.php script. Remote…EPSS 2.7%9.3CVE-2025-34186Ilevia eve x1 server firmware os command injection vulnerabilityIlevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() c…EPSS 0.87%9.3CVE-2025-34187Ilevia eve x1 server firmware os command injection vulnerabilityIlevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a misconfiguration in the sudoers file that allows passwordless execution of certain Bash sc…EPSS 3.2%

Source: NIST National Vulnerability Database (record CVE-2025-34515), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.