CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.8. Exploitation may require the attacker to be authenticated.
CVE
CVE-2025-34514
Severity
HIGH
CVSS
8.8
EPSS
2.04%
Original NVD Description
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection vulnerabilities in multiple web-accessible PHP scripts that call exec() and allow an authenticated attacker to execute arbitrary commands. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.
Related CVEs
Other vulnerabilities affecting the same vendor(s)