QSearchQSearch

CVE-2025-34186

9.8 CRITICAL

Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism

Published: 2025-09-16 · Last updated: 2026-05-26

Severity and scoring

CVSS
9.8 CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-287, CWE-78

Affected products

VendorProduct
ileviaeve_x1_server_firmware

Description

Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() call for authentication, allowing attackers to inject special characters and manipulate command parsing. Because the binary interprets non-zero exit codes from system() as successful authentication, remote attackers can bypass authentication and gain full access to the system.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2025-34512 Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a reflected cross-site scripting (XSS) vulnerability in index.php that all... (6.1 MEDIUM)

Same CWE

  • CVE-2026-12183 Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerabili... (9.8 CRITICAL)
  • CVE-2026-46716 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool (9.9 CRITICAL)
  • CVE-2026-42853 ApostropheCMS is an open-source Node.js content management system (6.5 MEDIUM)
  • CVE-2026-48165 MariaDB server is a community developed fork of MySQL server (8.0 HIGH)
  • CVE-2026-48163 MariaDB server is a community developed fork of MySQL server (8.0 HIGH)