← Back to browse · API

CVE-2025-34513

Severity
CRITICAL
CVSS
9.3
EPSS
0.07616
Risk score
39.87
CISA KEV
No
PoC
No
Published
2025-10-16
Modified
2026-05-15
First seen
2026-08-07
Aliases
EUVD-2025-34801, GHSA-XGVX-J695-6GJ9
Products
Ilevia Srl.:EVE X1 Server 0 ≤4.7.18.0.eden
Sources
euvd EUVD-2025-34801

Description

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_csv.php that allows an unauthenticated attacker to execute arbitrary code. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.

References