AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-34184

CRITICAL · CVSS 9.8 EPSS 2.74%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-09-16 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. It may be remotely exploitable. It may lead to a denial-of-service condition.

CVE
CVE-2025-34184
Severity
CRITICAL
CVSS
9.8
EPSS
2.74%

Original NVD Description

Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax/php/login.php script. Remote attackers can execute arbitrary system commands by injecting payloads into the 'passwd' HTTP POST parameter, leading to full system compromise or denial of service.

Related CVEs

Other vulnerabilities affecting the same vendor(s)