← Back to browse · API

CVE-2025-34515

Severity
CRITICAL
CVSS
9.3
EPSS
0.07449
Risk score
39.81
CISA KEV
No
PoC
No
Published
2025-10-16
Modified
2026-05-15
First seen
2026-08-07
Aliases
EUVD-2025-34804, GHSA-RV43-HP4F-HX6X
Products
Ilevia Srl.:EVE X1 Server 0 ≤4.7.18.0.eden
Sources
euvd EUVD-2025-34804

Description

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in sync_project.sh that allows an attacker to escalate privileges to root. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.

References