Home/Product/ilevia eve x1 server firmware
Product

ilevia eve x1 server firmware

16 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-60739
all versions
Cross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before, Logic Version
9.6CRITICAL
CVE-2025-60738
all versions
An issue in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before Logic Version v6.00 - 2025_07_21 and before allows a r
9.8CRITICAL
CVE-2025-60737
<= 4.7.18.0
Cross Site Scripting vulnerability in Ilevia EVE X1 Server Firmware Version<= 4.7.18.0.eden:Logic Version<=6.00 - 2025_07_21 allow
6.1MEDIUM
CVE-2025-34519
<= 4.7.18.0
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an insecure hashing algorithm vulnerability. The product stores
7.5HIGH
CVE-2025-34518
<= 4.7.18.0
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a relative path traversal vulnerability in get_file_content.ph
7.5HIGH
CVE-2025-34517
<= 4.7.18.0
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an absolute path traversal vulnerability in get_file_content.p
7.5HIGH
CVE-2025-34516
<= 4.7.18.0
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unaut
9.8CRITICAL
CVE-2025-34515
<= 4.7.18.0
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in sync_p
9.8CRITICAL
CVE-2025-34514
<= 4.7.18.0
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection vulnerabilities in multiple we
8.8HIGH
CVE-2025-34513
<= 4.7.18.0
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_csv.php
9.8CRITICAL
CVE-2025-34512
<= 4.7.18.0
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a reflected cross-site scripting (XSS) vulnerability in index.ph
6.1MEDIUM
CVE-2025-34187
<= 4.7.18.0
Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a misconfiguration in the sudoers file that allows passwordless executi
8.8HIGH
CVE-2025-34186
<= 4.7.18.0
Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is p
9.8CRITICAL
CVE-2025-34185
<= 4.7.18.0
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a pre-authentication file disclosure vulnerability via the 'db_log' POST p
7.5HIGH
CVE-2025-34184
<= 4.7.18.0
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax/php/log
9.8CRITICAL
CVE-2025-34183
<= 4.7.18.0
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows unauthent
7.5HIGH
threatengine.sh