---
id: CVE-2025-34512
title: "Ilevia\_EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a reflected cross-site scripting (XSS) vulnerability in index.php that allows an unauthenticated attacker to execute arbitrary script in the victim's browser.\_Ilevia has decl…"
summary: "Ilevia\_EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a reflected cross-site scripting (XSS) vulnerability in index.php that allows an unauthenticated attacker to execute arbitrary script in the victim's browser.\_Ilevia has decl…"
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: ilevia
product: eve_x1_server_firmware
affected:
  - eve_x1_server_firmware <= 4.7.18.0
published: '2025-10-16'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-34512'
references:
  - url: 'https://www.ilevia.com/'
    label: disclosure@vulncheck.com
  - url: 'https://www.vulncheck.com/advisories/ilevia-eve-x1-server-reflected-xss'
    label: disclosure@vulncheck.com
  - url: 'https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5961.php'
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00407
epssPercentile: 0.32892
ingestedAt: '2026-10-09T12:53:29.034Z'
---

## Overview

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a reflected cross-site scripting (XSS) vulnerability in index.php that allows an unauthenticated attacker to execute arbitrary script in the victim's browser. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.

## Affected

- `eve_x1_server_firmware <= 4.7.18.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
