CVE-2025-34186

CRITICAL WAF: High
CVSS 9.8 Published: 2025-09-16
CWE-78 CWE-287 CWE-78

Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() call for authentication, allowing attackers to inject special characters and manipulate command parsing. Due to the binary's interpretation of non-zero exit codes as successful authentication, remote attackers can bypass authentication and gain full access to the system.

WAF Coverage Analysis

OS Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution
Improper Authentication Low WAF Coverage

OWASP: A07:2021 Identification and Authentication Failures

OS Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
ileviaeve_x1_server_firmwareup to 4.7.18.0

References

Back to CVE Database