Ilevia develops the EVE X1 Server, an edge-computing and virtualization appliance whose vulnerability profile skews strongly toward critical-severity outcomes. The recurring weakness classes—OS command injection, path traversal, cross-site scripting, sensitive information exposure, and cross-site request forgery—reflect the appliance's web-facing management interface and command-execution capabilities, typical of administrative infrastructure where input validation and request authenticity are essential. Defenders should prioritize updates for this vendor's server firmware and restrict management access to trusted networks; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ilevia over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-34513CRITICAL Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_csv.php that allows an unauthenticated attacker to execute a | Oct 16, 2025 | 9.8 | 39 | NO | NO |
CVE-2025-34515CRITICAL Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in sync_project.sh that allows an attacker to escalate privile | Oct 16, 2025 | 9.8 | 35 | NO | NO |
CVE-2025-60739CRITICAL Cross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before, Logic Version v6.00 - 2025_07_21 allows a remote attacker to exe | Nov 25, 2025 | 9.6 | 33 | NO | NO |
CVE-2025-34184CRITICAL Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax/php/login.php script. Remote attackers can execute arbitrar | Sep 16, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-34516CRITICAL Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unauthenticated attacker to obtain remote access. Ilevia ha | Oct 16, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-34186CRITICAL Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() call for authentication, allowin | Sep 16, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-34187HIGH Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a misconfiguration in the sudoers file that allows passwordless execution of certain Bash scripts. If these scripts are wri | Sep 16, 2025 | 8.8 | 30 | NO | NO |
CVE-2025-60738CRITICAL An issue in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before Logic Version v6.00 - 2025_07_21 and before allows a remote attacker to execute arbitrary code via the p | Nov 20, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-34514HIGH Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection vulnerabilities in multiple web-accessible PHP scripts that call exec() and allow | Oct 16, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-34518HIGH Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a relative path traversal vulnerability in get_file_content.php that allows an attacker to read arbitrary files. Ilev | Oct 16, 2025 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ilevia.
Media articles that mention a CVE ID that affects a product developed by Ilevia — matched by CVE ID, not by vendor name.