CVE-2025-34184
Ilevia EVE X1 Server 4.7.18.0.eden Neuro-Core Unauthenticated Code Injection
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax/php/login.php script. Remote attackers can execute arbitrary system commands by injecting payloads into the 'passwd' HTTP POST parameter, leading to full system compromise or denial of service.
| CWE | CWE-78 |
| Vendor | ilevia srl. |
| Product | eve x1 server |
| Published | Sep 16, 2025 |
| Last Updated | Mar 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for ilevia srl. eve x1 server
Be the first to know when new unknown vulnerabilities affecting ilevia srl. eve x1 server are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Ilevia Srl. / EVE X1 Server
* ≤ 4.7.18.0.eden (Logic version: 6.00)
References
Credits
Gjoko Krstic of Zero Science Lab