📦 Eve X1 Server Firmware

by Ilevia

🔍 What is Eve X1 Server Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-60739

CRITICAL CVSS 9.6 Nov 25, 2025

A Cross-Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server firmware allows remote attackers to execute arbitrary code via the /bh_web_backend component. This affects Ilevia EVE X1 Serve...

CVE-2025-60738

CRITICAL CVSS 9.8 Nov 20, 2025

This vulnerability allows remote attackers to execute arbitrary operating system commands on Ilevia EVE X1 Server devices via the ping.php component, which fails to properly sanitize IP address parame...

CVE-2025-34516

CRITICAL CVSS 9.8 Oct 16, 2025

Ilevia EVE X1 Server firmware versions up to 4.7.18.0.eden contain hardcoded default credentials that allow unauthenticated remote attackers to gain administrative access. This affects all customers r...

CVE-2025-34513

CRITICAL CVSS 9.8 Oct 16, 2025

Ilevia EVE X1 Server firmware contains an unauthenticated OS command injection vulnerability in mbus_build_from_csv.php that allows remote attackers to execute arbitrary code. This affects all firmwar...

CVE-2025-34515

CRITICAL CVSS 9.8 Oct 16, 2025

CVE-2025-34515 is a privilege escalation vulnerability in Ilevia EVE X1 Server firmware where the sync_project.sh script runs with unnecessary root privileges. Attackers can exploit this to gain full ...

CVE-2025-34184

CRITICAL CVSS 9.8 Sep 16, 2025

This critical vulnerability allows unauthenticated remote attackers to execute arbitrary operating system commands on Ilevia EVE X1 Server systems. Attackers can achieve full system compromise by inje...

CVE-2025-34186

CRITICAL CVSS 9.8 Sep 16, 2025

This vulnerability allows remote attackers to bypass authentication on Ilevia EVE X1/X5 Server by injecting special characters into the authentication mechanism. Attackers can gain full system access ...

CVE-2025-34518

HIGH CVSS 7.5 Oct 16, 2025

CVE-2025-34518 is a relative path traversal vulnerability in Ilevia EVE X1 Server firmware that allows attackers to read arbitrary files on the system. This affects all firmware versions ≤ 4.7.18.0....

CVE-2025-34183

HIGH CVSS 7.5 Sep 16, 2025

This vulnerability allows unauthenticated remote attackers to retrieve plaintext credentials from exposed log files in Ilevia EVE X1 Server. It enables full authentication bypass and system compromise...

CVE-2025-60737

MEDIUM CVSS 6.1 Nov 20, 2025

This Cross-Site Scripting (XSS) vulnerability in Ilevia EVE X1 Server firmware allows remote attackers to inject malicious scripts via the /index.php component. Attackers can execute arbitrary code in...

CVE-2025-34512

MEDIUM CVSS 6.1 Oct 16, 2025

Ilevia EVE X1 Server firmware versions up to 4.7.18.0.eden contain a reflected cross-site scripting vulnerability in index.php that allows unauthenticated attackers to execute arbitrary JavaScript in ...