πŸ” CVE Alert

CVE-2025-14276

MEDIUM 5.6

Ilevia EVE X1 Server leaf_search.php command injection

CVSS Score
5.6
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was determined in Ilevia EVE X1 Server up to 4.6.5.0.eden. Impacted is an unknown function of the file /ajax/php/leaf_search.php. This manipulation of the argument line causes command injection. The attack can be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is considered difficult. The exploit has been publicly disclosed and may be utilized. Upgrading the affected component is recommended. The vendor confirms the issue and recommends: "We already know that issue and on most devices are already solved, also it’s not needed to open the port to outside world so we advised our customer to close it".

CWE CWE-77 CWE-74
Vendor ilevia
Product eve x1 server
Published Dec 8, 2025
Last Updated Feb 24, 2026
Stay Ahead of the Next One

Get instant alerts for ilevia eve x1 server

Be the first to know when new medium vulnerabilities affecting ilevia eve x1 server are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Ilevia / EVE X1 Server
4.6.5.0.eden

References

NVD β†— CVE.org β†— EPSS Data β†—
vuldb.com: https://vuldb.com/?id.334802 vuldb.com: https://vuldb.com/?ctiid.334802 vuldb.com: https://vuldb.com/?submit.702649 vuldb.com: https://vuldb.com/?submit.715521 yuque.com: https://www.yuque.com/yuqueyonghuexlgkz/zepczx/ahygt5u6sgqpk5tt?singleDoc

Credits

πŸ” niix330 (VulDB User)