Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unauthenticated attacker to obtain remote access. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.
References
| Link | Resource |
|---|---|
| https://www.ilevia.com/ | Product |
| https://www.vulncheck.com/advisories/ilevia-eve-x1-server-use-of-default-credentials | Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
23 Oct 2025, 19:19
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Ilevia eve X1 Server
Ilevia eve X1 Server Firmware Ilevia |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| CPE | cpe:2.3:h:ilevia:eve_x1_server:-:*:*:*:*:*:*:* cpe:2.3:o:ilevia:eve_x1_server_firmware:*:*:*:*:*:*:*:* |
|
| References | () https://www.ilevia.com/ - Product | |
| References | () https://www.vulncheck.com/advisories/ilevia-eve-x1-server-use-of-default-credentials - Third Party Advisory |
16 Oct 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-16 18:15
Updated : 2025-10-23 19:19
NVD link : CVE-2025-34516
Mitre link : CVE-2025-34516
CVE.ORG link : CVE-2025-34516
JSON object : View
Products Affected
ilevia
- eve_x1_server
- eve_x1_server_firmware
CWE
CWE-1392
Use of Default Credentials
