Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a pre-authentication file disclosure vulnerability via the 'db_log' POST parameter. Remote attackers can retrieve arbitrary files from the server, exposing sensitive system information and credentials.
                
            References
                    | Link | Resource | 
|---|---|
| https://packetstorm.news/files/id/207716/ | Third Party Advisory | 
| https://www.ilevia.com/ | Product | 
| https://www.vulncheck.com/advisories/ilevia-eve-x1-server-unauth-file-disclosure | Third Party Advisory | 
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5955.php | Third Party Advisory | 
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5955.php | Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
            
            
 
  | 
    
History
                    25 Sep 2025, 14:56
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:h:ilevia:eve_x1:-:*:*:*:*:*:*:*  | 
    cpe:2.3:o:ilevia:eve_x1_server_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:ilevia:eve_x1_server:-:*:*:*:*:*:*:*  | 
| First Time | 
        
        Ilevia eve X1 Server Firmware
         Ilevia eve X1 Server  | 
24 Sep 2025, 16:14
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time | 
        
        Ilevia eve X1 Firmware
         Ilevia Ilevia eve X1  | 
|
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 7.5  | 
| CPE | cpe:2.3:o:ilevia:eve_x1_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:ilevia:eve_x1:-:*:*:*:*:*:*:*  | 
|
| References | () https://packetstorm.news/files/id/207716/ - Third Party Advisory | |
| References | () https://www.ilevia.com/ - Product | |
| References | () https://www.vulncheck.com/advisories/ilevia-eve-x1-server-unauth-file-disclosure - Third Party Advisory | |
| References | () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5955.php - Third Party Advisory | 
17 Sep 2025, 14:18
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5955.php - | 
16 Sep 2025, 20:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-09-16 20:15
Updated : 2025-09-25 14:56
NVD link : CVE-2025-34185
Mitre link : CVE-2025-34185
CVE.ORG link : CVE-2025-34185
JSON object : View
Products Affected
                ilevia
- eve_x1_server_firmware
 - eve_x1_server
 
