CVE-2025-34185
published 2025-09-16CVE-2025-34185: Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a pre-authentication file disclosure vulnerability via the 'db_log' POST parameter. Remote attackers can…
PriorityP350high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.80%
52.0th percentile
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a pre-authentication file disclosure vulnerability via the 'db_log' POST parameter. Remote attackers can retrieve arbitrary files from the server, exposing sensitive system information and credentials.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ilevia | eve_x1_server_firmware | <= 4.7.18.0 | — |
| ilevia_srl | eve_x1_server | <= 4.7.18.0.eden | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-65x8-f79x-273x: Ilevia EVE X1 Server version ≤ 4
ghsa_unreviewed·2025-09-16
CVE-2025-34185 [HIGH] CWE-22 GHSA-65x8-f79x-273x: Ilevia EVE X1 Server version ≤ 4
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a pre-authentication file disclosure vulnerability via the 'db_log' POST parameter. Remote attackers can retrieve arbitrary files from the server, exposing sensitive system information and credentials.
CISA ICS
Ilevia EVE X1 Server
cisa_ics·2026-02-05·CVSS 7.5
[HIGH] Ilevia EVE X1 Server
ICS Advisory
##
Ilevia EVE X1 Server
Release DateFebruary 05, 2026
Alert CodeICSA-26-036-04
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary shell commands and the disclosure of sensitive system information.
The following versions of Ilevia EVE X1 Server are affected:
- EVE X1 <=4.7.18.0 (CVE-2025-34185, CVE-2025-34184, CVE-2025-34183, CVE-2025-34186, CVE-2025-34187, CVE-2025-34517, CVE-2025-34518, CVE-2025-34512, CVE-2025-34513)
CVSS
Vendor
Equipment
Vulnerabilities
| v3 9.8
| Ilevia
| Ilevia EVE X1 Server
| Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutraliz
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-09-16
Published