Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a pre-authentication file disclosure vulnerability via the 'db_log' POST parameter. Remote attackers can retrieve arbitrary files from the server, exposing sensitive system information and credentials.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-29646 Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a pre-authentication file disclosure vulnerability via the 'db_log' POST parameter. Remote attackers can retrieve arbitrary files from the server, exposing sensitive system information and credentials.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 26 Sep 2025 00:00:00 +0900

Type Values Removed Values Added
First Time appeared Ilevia eve X1 Server Firmware
CPEs cpe:2.3:h:ilevia:eve_x1:-:*:*:*:*:*:*:*
cpe:2.3:o:ilevia:eve_x1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ilevia:eve_x1_server:-:*:*:*:*:*:*:*
cpe:2.3:o:ilevia:eve_x1_server_firmware:*:*:*:*:*:*:*:*
Vendors & Products Ilevia eve X1
Ilevia eve X1 Firmware
Ilevia eve X1 Server Firmware

Thu, 25 Sep 2025 01:15:00 +0900

Type Values Removed Values Added
First Time appeared Ilevia eve X1
Ilevia eve X1 Firmware
CPEs cpe:2.3:h:ilevia:eve_x1:-:*:*:*:*:*:*:*
cpe:2.3:o:ilevia:eve_x1_firmware:*:*:*:*:*:*:*:*
Vendors & Products Ilevia eve X1
Ilevia eve X1 Firmware
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Wed, 17 Sep 2025 23:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 17 Sep 2025 20:00:00 +0900

Type Values Removed Values Added
First Time appeared Ilevia
Ilevia eve X1 Server
Vendors & Products Ilevia
Ilevia eve X1 Server

Wed, 17 Sep 2025 05:00:00 +0900

Type Values Removed Values Added
Description Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a pre-authentication file disclosure vulnerability via the 'db_log' POST parameter. Remote attackers can retrieve arbitrary files from the server, exposing sensitive system information and credentials.
Title Ilevia EVE X1 Server 4.7.18.0.eden Unauthenticated File Disclosure
Weaknesses CWE-200
CWE-22
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-11-28T16:09:53.000Z

Reserved: 2025-04-15T19:15:22.568Z

Link: CVE-2025-34185

cve-icon Vulnrichment

Updated: 2025-09-17T13:58:09.403Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-16T20:15:34.577

Modified: 2025-09-25T14:56:39.847

Link: CVE-2025-34185

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-17T19:52:07Z

Weaknesses