CVE-2025-34183
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attackers to retrieve plaintext credentials from exposed .log files.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.70%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attackers to retrieve plaintext credentials from exposed .log files. This flaw enables full authentication bypass and system compromise through credential reuse.
- CVSS 4.0
- 9.3 CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.70% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-532
- Affected
- ilevia/eve x1 server firmware
- Source
- disclosure@vulncheck.com
References
- https://packetstorm.news/files/id/208700/Exploit, Third Party Advisory
- https://www.ilevia.com/Product
- https://www.vulncheck.com/advisories/ilevia-eve-x1-server-credentials-leak-through-log-disclosureThird Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5957.phpExploit, Release Notes, Third Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5957.phpExploit, Release Notes, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.