CVE-2025-34513
- EPSS 14.51%
- Veröffentlicht 16.10.2025 17:53:34
- Zuletzt bearbeitet 23.10.2025 19:28:18
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_csv.php that allows an unauthenticated attacker to execute arbitrary code. Ilevia has declined to service this vulnerability, and ...
CVE-2025-34516
- EPSS 0.18%
- Veröffentlicht 16.10.2025 17:52:55
- Zuletzt bearbeitet 03.11.2025 19:15:52
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unauthenticated attacker to obtain remote access. Ilevia has declined to service this vulnerability, and recommends that customer...
CVE-2025-34187
- EPSS 0.81%
- Veröffentlicht 16.09.2025 19:45:42
- Zuletzt bearbeitet 25.09.2025 14:51:36
Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a misconfiguration in the sudoers file that allows passwordless execution of certain Bash scripts. If these scripts are writable by web-facing users or accessible via command injection, attacke...
CVE-2025-34186
- EPSS 1.67%
- Veröffentlicht 16.09.2025 19:45:01
- Zuletzt bearbeitet 25.09.2025 14:56:49
Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() call for authentication, allowing attackers to inject special characters and manipulate command parsin...
CVE-2025-34185
- EPSS 0.25%
- Veröffentlicht 16.09.2025 19:44:26
- Zuletzt bearbeitet 25.09.2025 14:56:39
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a pre-authentication file disclosure vulnerability via the 'db_log' POST parameter. Remote attackers can retrieve arbitrary files from the server, exposing sensitive system information and credent...
CVE-2025-34184
- EPSS 1.83%
- Veröffentlicht 16.09.2025 19:40:41
- Zuletzt bearbeitet 25.09.2025 14:56:30
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax/php/login.php script. Remote attackers can execute arbitrary system commands by injecting payloads into the 'passwd' HTTP POST pa...
CVE-2025-34183
- EPSS 0.26%
- Veröffentlicht 16.09.2025 19:39:20
- Zuletzt bearbeitet 25.09.2025 14:56:22
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attackers to retrieve plaintext credentials from exposed .log files. This flaw enables full authentication b...