Ilevia
Ilevia EVE X1 Server Firmware: vulnerabilidades y CVE
Ilevia EVE X1 Server Firmware tiene 16 vulnerabilidades publicadas, 11 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses11
Críticas9
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-60739 | Crítica (9.6) | 0.32% | — | 25 nov 2025 | Cross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before, Logic Version v6.00 - 2025_07_21 allows a remote attacker to execute arbitrary code via the… |
| CVE-2025-60738 | Crítica (9.8) | 1.0% | — | 20 nov 2025 | An issue in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before Logic Version v6.00 - 2025_07_21 and before allows a remote attacker to execute arbitrary code via the ping.php component does not perform… |
| CVE-2025-60737 | Media (6.1) | 0.32% | — | 20 nov 2025 | Cross Site Scripting vulnerability in Ilevia EVE X1 Server Firmware Version<= 4.7.18.0.eden:Logic Version<=6.00 - 2025_07_21 allows a remote attacker to execute arbitrary code via the /index.php component |
| CVE-2025-34519 | Alta (8.2) | 0.31% | — | 16 oct 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an insecure hashing algorithm vulnerability. The product stores passwords using the MD5 hash function without applying a per‑password salt. Because MD5 is a… |
| CVE-2025-34518 | Alta (8.7) | 0.66% | — | 16 oct 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a relative path traversal vulnerability in get_file_content.php that allows an attacker to read arbitrary files. Ilevia has declined to service this… |
| CVE-2025-34517 | Alta (8.7) | 0.66% | — | 16 oct 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an absolute path traversal vulnerability in get_file_content.php that allows an attacker to read arbitrary files. Ilevia has declined to service this… |
| CVE-2025-34516 | Crítica (9.3) | 0.58% | — | 16 oct 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unauthenticated attacker to obtain remote access. Ilevia has declined to service this… |
| CVE-2025-34515 | Crítica (9.3) | 8.0% | — | 16 oct 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in sync_project.sh that allows an attacker to escalate privileges to root. Ilevia has declined to… |
| CVE-2025-34514 | Alta (8.7) | 2.0% | — | 16 oct 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection vulnerabilities in multiple web-accessible PHP scripts that call exec() and allow an authenticated attacker to execute… |
| CVE-2025-34513 | Crítica (9.3) | 7.6% | — | 16 oct 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_csv.php that allows an unauthenticated attacker to execute arbitrary code. Ilevia has declined to… |
| CVE-2025-34512 | Media (5.1) | 0.41% | — | 16 oct 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a reflected cross-site scripting (XSS) vulnerability in index.php that allows an unauthenticated attacker to execute arbitrary script in the victim's… |
| CVE-2025-34187 | Crítica (9.3) | 3.2% | — | 16 sept 2025 | Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a misconfiguration in the sudoers file that allows passwordless execution of certain Bash scripts. If these scripts are writable by web-facing users or accessible… |
| CVE-2025-34186 | Crítica (9.3) | 0.87% | — | 16 sept 2025 | Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() call for authentication, allowing attackers to inject special… |
| CVE-2025-34185 | Alta (8.7) | 0.84% | — | 16 sept 2025 | Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a pre-authentication file disclosure vulnerability via the 'db_log' POST parameter. Remote attackers can retrieve arbitrary files from the server, exposing sensitive… |
| CVE-2025-34184 | Crítica (9.3) | 2.7% | — | 16 sept 2025 | Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax/php/login.php script. Remote attackers can execute arbitrary system commands by injecting payloads… |
| CVE-2025-34183 | Crítica (9.3) | 0.70% | — | 16 sept 2025 | Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attackers to retrieve plaintext credentials from exposed .log files. This… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.