---
id: CVE-2025-14276
title: A vulnerability was determined in Ilevia EVE X1 Server up to 4.6.5.0.eden
summary: >-
  A vulnerability was determined in Ilevia EVE X1 Server up to 4.6.5.0.eden.
  Impacted is an unknown function of the file /ajax/php/leaf_search.php. This
  manipulation of the argument line causes command injection. The attack can be
  initiate…
severity: medium
cvss: 5.6
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-77
published: '2025-12-08'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14276'
references:
  - url: 'https://vuldb.com/?ctiid.334802'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.334802'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.702649'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.715521'
    label: cna@vuldb.com
  - url: 'https://www.yuque.com/yuqueyonghuexlgkz/zepczx/ahygt5u6sgqpk5tt?singleDoc'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.01632
epssPercentile: 0.75475
ingestedAt: '2026-10-07T20:46:46.775Z'
---

## Overview

A vulnerability was determined in Ilevia EVE X1 Server up to 4.6.5.0.eden. Impacted is an unknown function of the file /ajax/php/leaf_search.php. This manipulation of the argument line causes command injection. The attack can be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is considered difficult. The exploit has been publicly disclosed and may be utilized. Upgrading the affected component is recommended. The vendor confirms the issue and recommends: "We already know that issue and on most devices are already solved, also it’s not needed to open the port to outside world so we advised our customer to close it".

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
