CVEs (16)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Cross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before, Logic Version v6.00 - 2025_07_21 allows a remote attacker to execute arbitrary code via the /bh_web_back...Show more |
An issue in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before Logic Version v6.00 - 2025_07_21 and before allows a remote attacker to execute arbitrary code via the ping.php component does not perform secur...Show more |
Cross Site Scripting vulnerability in Ilevia EVE X1 Server Firmware Version<= 4.7.18.0.eden:Logic Version<=6.00 - 2025_07_21 allows a remote attacker to execute arbitrary code via the /index.php component |
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an insecure hashing algorithm vulnerability. The product stores passwords using the MD5 hash function without applying a per‑password salt. Because MD5 is a...Show more |
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a relative path traversal vulnerability in get_file_content.php that allows an attacker to read arbitrary files. Ilevia has declined to service this vulnerab...Show more |
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an absolute path traversal vulnerability in get_file_content.php that allows an attacker to read arbitrary files. Ilevia has declined to service this vulnera...Show more |
1Ilevia 1Eve X1 Server Firmware Nov 3, 2025 Oct 16, 2025 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unauthenticated attacker to obtain remote access. Ilevia has declined to service this vulnerability...Show more |
1Ilevia 1Eve X1 Server Firmware Nov 6, 2025 Oct 16, 2025 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in sync_project.sh that allows an attacker to escalate privileges to root. Ilevia has declined to serv...Show more |
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection vulnerabilities in multiple web-accessible PHP scripts that call exec() and allow an authenticated attacker to execute arb...Show more |
1Ilevia 1Eve X1 Server Firmware Oct 23, 2025 Oct 16, 2025 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_csv.php that allows an unauthenticated attacker to execute arbitrary code. Ilevia has declined to se...Show more |
1Ilevia 1Eve X1 Server Firmware May 26, 2026 Oct 16, 2025 5.1 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a reflected cross-site scripting (XSS) vulnerability in index.php that allows an unauthenticated attacker to execute arbitrary script in the victim's browser...Show more |
1Ilevia 1Eve X1 Server Firmware Sep 25, 2025 Sep 16, 2025 9.3 CRITICAL· v4 8.8 HIGH· v3 N/A· v2 Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a misconfiguration in the sudoers file that allows passwordless execution of certain Bash scripts. If these scripts are writable by web-facing users or accessible...Show more |
1Ilevia 1Eve X1 Server Firmware May 26, 2026 Sep 16, 2025 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() call for authentication, allowing attackers to inject special characters...Show more |
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a pre-authentication file disclosure vulnerability via the 'db_log' POST parameter. Remote attackers can retrieve arbitrary files from the server, exposing sensitive...Show more |
1Ilevia 1Eve X1 Server Firmware Sep 25, 2025 Sep 16, 2025 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax/php/login.php script. Remote attackers can execute arbitrary system commands by injecting payloads...Show more |
1Ilevia 1Eve X1 Server Firmware Sep 25, 2025 Sep 16, 2025 9.3 CRITICAL· v4 7.5 HIGH· v3 N/A· v2 Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attackers to retrieve plaintext credentials from exposed .log files. This flaw...Show more |