---
id: CVE-2025-34514
title: "Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection vulnerabilities in multiple web-accessible PHP scripts that call exec() and allow an authenticated attacker to execute arbitrary commands.\_…"
summary: "Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection vulnerabilities in multiple web-accessible PHP scripts that call exec() and allow an authenticated attacker to execute arbitrary commands.\_…"
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: ilevia
product: eve_x1_server_firmware
affected:
  - eve_x1_server_firmware <= 4.7.18.0
published: '2025-10-16'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-34514'
references:
  - url: 'https://www.ilevia.com/'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/ilevia-eve-x1-server-auth-command-injection
    label: disclosure@vulncheck.com
  - url: 'https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5966.php'
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.01992
epssPercentile: 0.80035
ingestedAt: '2026-10-09T12:53:29.035Z'
---

## Overview

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection vulnerabilities in multiple web-accessible PHP scripts that call exec() and allow an authenticated attacker to execute arbitrary commands. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.

## Affected

- `eve_x1_server_firmware <= 4.7.18.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
