Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unauthenticated attacker to obtain remote access. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.
References
| Link | Resource |
|---|---|
| https://www.ilevia.com/ | Product |
| https://www.vulncheck.com/advisories/ilevia-eve-x1-server-use-of-default-credentials | Third Party Advisory |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5963.php |
Configurations
Configuration 1 (hide)
| AND |
|
History
03 Nov 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
23 Oct 2025, 19:19
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| First Time |
Ilevia
Ilevia eve X1 Server Firmware Ilevia eve X1 Server |
|
| CPE | cpe:2.3:o:ilevia:eve_x1_server_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:ilevia:eve_x1_server:-:*:*:*:*:*:*:* |
|
| References | () https://www.ilevia.com/ - Product | |
| References | () https://www.vulncheck.com/advisories/ilevia-eve-x1-server-use-of-default-credentials - Third Party Advisory |
16 Oct 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-16 18:15
Updated : 2025-11-03 19:15
NVD link : CVE-2025-34516
Mitre link : CVE-2025-34516
CVE.ORG link : CVE-2025-34516
JSON object : View
Products Affected
ilevia
- eve_x1_server_firmware
- eve_x1_server
CWE
CWE-1392
Use of Default Credentials
