CVE-2025-34186: Ilevia Eve x1 Server Firmware

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() call for authentication, allowing attackers to inject special characters and manipulate command parsing. Because the binary interprets non-zero exit codes from system() as successful authentication, remote attackers can bypass authentication and gain full access to the system.

Affected products

  • Ilevia Eve x1 Server Firmware: up to and including 4.7.18.0

Published 2025-09-16. Last modified 2026-06-17.