AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-34514

HIGH · CVSS 8.8 EPSS 2.04%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-10-16 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.8. Exploitation may require the attacker to be authenticated.

CVE
CVE-2025-34514
Severity
HIGH
CVSS
8.8
EPSS
2.04%

Original NVD Description

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection vulnerabilities in multiple web-accessible PHP scripts that call exec() and allow an authenticated attacker to execute arbitrary commands. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.

Related CVEs

Other vulnerabilities affecting the same vendor(s)