OS Command Injection Vulnerability in Ilevia EVE X1 Server Firmware
CVE-2025-34513
Key Information:
- Vendor
Ilevia Srl.
- Status
- Vendor
- CVE Published:
- 16 October 2025
Badges
What is CVE-2025-34513?
The Ilevia EVE X1 Server firmware versions up to 4.7.18.0.eden are vulnerable to an OS command injection flaw in the mbus_build_from_csv.php script. This vulnerability enables unauthenticated attackers to execute arbitrary code remotely. Ilevia has advised users to mitigate the risk by avoiding exposure of port 8080 to the internet, but has chosen not to patch the vulnerability. This leaves systems potentially open to exploitation, underscoring the need for stringent security measures.
Affected Version(s)
EVE X1 Server * <= 4.7.18.0.eden
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved