CVE-2025-34184
16.09.2025, 20:15
Ilevia EVE X1 Server version 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax/php/login.php script. Remote attackers can execute arbitrary system commands by injecting payloads into the 'passwd' HTTP POST parameter, leading to full system compromise or denial of service.
| Vendor | Product | Version |
|---|---|---|
| ilevia | eve_x1_server_firmware | 𝑥 ≤ 4.7.18.0 |
𝑥
= Vulnerable software versions