Ilevia

Eve X1 Server Firmware

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 14.51%
  • Veröffentlicht 16.10.2025 17:53:34
  • Zuletzt bearbeitet 23.10.2025 19:28:18

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_csv.php that allows an unauthenticated attacker to execute arbitrary code. Ilevia has declined to service this vulnerability, and ...

  • EPSS 0.18%
  • Veröffentlicht 16.10.2025 17:52:55
  • Zuletzt bearbeitet 03.11.2025 19:15:52

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unauthenticated attacker to obtain remote access. Ilevia has declined to service this vulnerability, and recommends that customer...

Exploit
  • EPSS 0.81%
  • Veröffentlicht 16.09.2025 19:45:42
  • Zuletzt bearbeitet 25.09.2025 14:51:36

Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a misconfiguration in the sudoers file that allows passwordless execution of certain Bash scripts. If these scripts are writable by web-facing users or accessible via command injection, attacke...

Exploit
  • EPSS 1.67%
  • Veröffentlicht 16.09.2025 19:45:01
  • Zuletzt bearbeitet 25.09.2025 14:56:49

Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() call for authentication, allowing attackers to inject special characters and manipulate command parsin...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 16.09.2025 19:44:26
  • Zuletzt bearbeitet 25.09.2025 14:56:39

Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a pre-authentication file disclosure vulnerability via the 'db_log' POST parameter. Remote attackers can retrieve arbitrary files from the server, exposing sensitive system information and credent...

Exploit
  • EPSS 1.83%
  • Veröffentlicht 16.09.2025 19:40:41
  • Zuletzt bearbeitet 25.09.2025 14:56:30

Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax/php/login.php script. Remote attackers can execute arbitrary system commands by injecting payloads into the 'passwd' HTTP POST pa...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 16.09.2025 19:39:20
  • Zuletzt bearbeitet 25.09.2025 14:56:22

Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attackers to retrieve plaintext credentials from exposed .log files. This flaw enables full authentication b...