AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-34512

MEDIUM · CVSS 6.1 EPSS 0.38%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-10-16 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.1. Exploitation may require the attacker to be authenticated.

CVE
CVE-2025-34512
Severity
MEDIUM
CVSS
6.1
EPSS
0.38%

Original NVD Description

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a reflected cross-site scripting (XSS) vulnerability in index.php that allows an unauthenticated attacker to execute arbitrary script in the victim's browser. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.

Related CVEs

Other vulnerabilities affecting the same vendor(s)