Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ilevia

First CVE: Sep 16, 2025Active for: 1 yearTotal CVEs: 16
55.9
VTI Score
TOP TARGET

Ilevia develops the EVE X1 Server, an edge-computing and virtualization appliance whose vulnerability profile skews strongly toward critical-severity outcomes. The recurring weakness classes—OS command injection, path traversal, cross-site scripting, sensitive information exposure, and cross-site request forgery—reflect the appliance's web-facing management interface and command-execution capabilities, typical of administrative infrastructure where input validation and request authenticity are essential. Defenders should prioritize updates for this vendor's server firmware and restrict management access to trusted networks; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
8.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
8.5
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ilevia over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 16, 2025
10 months ago
Most Recent CVE
Nov 25, 2025
241 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-34513CRITICAL
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_csv.php that allows an unauthenticated attacker to execute a
Oct 16, 20259.839NONO
CVE-2025-34515CRITICAL
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in sync_project.sh that allows an attacker to escalate privile
Oct 16, 20259.835NONO
CVE-2025-60739CRITICAL
Cross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before, Logic Version v6.00 - 2025_07_21 allows a remote attacker to exe
Nov 25, 20259.633NONO
CVE-2025-34184CRITICAL
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax/php/login.php script. Remote attackers can execute arbitrar
Sep 16, 20259.832NONO
CVE-2025-34516CRITICAL
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unauthenticated attacker to obtain remote access. Ilevia ha
Oct 16, 20259.831NONO
CVE-2025-34186CRITICAL
Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() call for authentication, allowin
Sep 16, 20259.831NONO
CVE-2025-34187HIGH
Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a misconfiguration in the sudoers file that allows passwordless execution of certain Bash scripts. If these scripts are wri
Sep 16, 20258.830NONO
CVE-2025-60738CRITICAL
An issue in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before Logic Version v6.00 - 2025_07_21 and before allows a remote attacker to execute arbitrary code via the p
Nov 20, 20259.829NONO
CVE-2025-34514HIGH
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection vulnerabilities in multiple web-accessible PHP scripts that call exec() and allow
Oct 16, 20258.828NONO
CVE-2025-34518HIGH
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a relative path traversal vulnerability in get_file_content.php that allows an attacker to read arbitrary files. Ilev
Oct 16, 20257.525NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
13%
44%
44%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network16 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (81.3%)
Unknown0 (0.0%)
Required3 (18.8%)
Privileges Required
Low2 (12.5%)
High0 (0.0%)
None14 (87.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ilevia.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ilevia — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ilevia's Products

View all 2 CNAs →

Top CWEs