Insecure Hashing Algorithm in Ilevia EVE X1 Server Firmware
CVE-2025-34519

8.2HIGH

Key Information:

Vendor
CVE Published:
16 October 2025

What is CVE-2025-34519?

The Ilevia EVE X1 Server firmware contains a vulnerability due to the use of the MD5 hashing function for password storage without applying a per-password salt. This design flaw allows attackers to exploit the stored password database effectively through offline dictionary, rainbow-table, or brute-force methods to retrieve original passwords. Ilevia advises users to prevent external exposure of port 8080 as a security measure in response to this vulnerability.

Affected Version(s)

EVE X1 Server * <= 4.7.18.0.eden

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gjoko Krstic of Zero Science Lab
.
CVE-2025-34519 : Insecure Hashing Algorithm in Ilevia EVE X1 Server Firmware