CVE-2025-34512 Details
Description
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a reflected cross-site scripting (XSS) vulnerability in index.php that allows an unauthenticated attacker to execute arbitrary script in the victim's browser. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.
A reflected cross-site scripting vulnerability has been identified in the Ilevia EVE X1 Server firmware versions through 4.7.18.0.eden. The issue resides in index.php, where input from the GET parameter 'error' is not properly sanitized. This vulnerability allows an unauthenticated attacker to execute arbitrary HTML or JavaScript in the context of the user's browser session on the affected site. Ilevia has chosen not to address this vulnerability and advises customers to keep port 8080 closed to external access.
Ilevia recommends not exposing port 8080 to the internet.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 16, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ilevia.com/ | [email protected] | Product |
| https://www.vulncheck.com/advisories/ilevia-eve-x1-server-reflected-xss | [email protected] | Third Party Advisory |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5961.php | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ilevia eve x1 server firmware | <= 4.7.18.0 |
CPE
Remediation
| |
| ilevia eve x1 server | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 26, 2026 | CVE Modified | [email protected] |
| Oct 23, 2025 | Initial Analysis | [email protected] |
| Oct 16, 2025 | New CVE Received | [email protected] |