CVE-2025-34519 Details
Description
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an insecure hashing algorithm vulnerability. The product stores passwords using the MD5 hash function without applying a per‑password salt. Because MD5 is a fast, unsalted hash, an attacker who obtains the password database can efficiently perform offline dictionary, rainbow‑table, or brute‑force attacks to recover the original passwords. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.
A vulnerability exists in Ilevia EVE X1 Server firmware versions through 4.7.18.0.eden, where passwords are stored using the MD5 hashing algorithm without a per-password salt. This unsalted hash allows attackers to efficiently execute offline dictionary, rainbow-table, or brute-force attacks to recover original passwords. Ilevia has chosen not to address this vulnerability and advises customers to avoid exposing port 8080 to the internet.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-327 | Use of a Broken or Risky Cryptographic Algorithm | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ilevia eve x1 server firmware | <= 4.7.18.0 |
CPE
Remediation
| |
| ilevia eve x1 server | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 6, 2025 | CVE Modified | [email protected] |
| Oct 23, 2025 | Initial Analysis | [email protected] |
| Oct 16, 2025 | New CVE Received | [email protected] |