Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attackers to retrieve plaintext credentials from exposed .log files. This flaw enables full authentication bypass and system compromise through credential reuse.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-29648 Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attackers to retrieve plaintext credentials from exposed .log files. This flaw enables full authentication bypass and system compromise through credential reuse.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 26 Sep 2025 00:00:00 +0900

Type Values Removed Values Added
First Time appeared Ilevia eve X1 Server Firmware
CPEs cpe:2.3:h:ilevia:eve_x1:-:*:*:*:*:*:*:*
cpe:2.3:o:ilevia:eve_x1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ilevia:eve_x1_server:-:*:*:*:*:*:*:*
cpe:2.3:o:ilevia:eve_x1_server_firmware:*:*:*:*:*:*:*:*
Vendors & Products Ilevia eve X1
Ilevia eve X1 Firmware
Ilevia eve X1 Server Firmware

Tue, 23 Sep 2025 04:00:00 +0900

Type Values Removed Values Added
First Time appeared Ilevia eve X1
Ilevia eve X1 Firmware
CPEs cpe:2.3:h:ilevia:eve_x1:-:*:*:*:*:*:*:*
cpe:2.3:o:ilevia:eve_x1_firmware:*:*:*:*:*:*:*:*
Vendors & Products Ilevia eve X1
Ilevia eve X1 Firmware
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Thu, 18 Sep 2025 00:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 17 Sep 2025 20:00:00 +0900

Type Values Removed Values Added
First Time appeared Ilevia
Ilevia eve X1 Server
Vendors & Products Ilevia
Ilevia eve X1 Server

Wed, 17 Sep 2025 05:00:00 +0900

Type Values Removed Values Added
Description Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attackers to retrieve plaintext credentials from exposed .log files. This flaw enables full authentication bypass and system compromise through credential reuse.
Title Ilevia EVE X1 Server 4.7.18.0.eden Credentials Leak Through Log Disclosure
Weaknesses CWE-532
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-11-28T16:10:23.336Z

Reserved: 2025-04-15T19:15:22.568Z

Link: CVE-2025-34183

cve-icon Vulnrichment

Updated: 2025-09-17T14:41:44.323Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-16T20:15:34.287

Modified: 2025-09-25T14:56:22.493

Link: CVE-2025-34183

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-17T19:52:08Z

Weaknesses