Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax/php/login.php script. Remote attackers can execute arbitrary system commands by injecting payloads into the 'passwd' HTTP POST parameter, leading to full system compromise or denial of service.
CVSS
No CVSS.
References
Configurations
No configuration.
History
17 Sep 2025, 14:18
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5956.php - |
16 Sep 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-16 20:15
Updated : 2025-09-17 14:18
NVD link : CVE-2025-34184
Mitre link : CVE-2025-34184
CVE.ORG link : CVE-2025-34184
JSON object : View
Products Affected
No product.
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')