CVE-2025-60739 Details
Description
Cross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before, Logic Version v6.00 - 2025_07_21 allows a remote attacker to execute arbitrary code via the /bh_web_backend component
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Ilevia EVE X1 Server Firmware Version 4.7.18.0.eden and earlier, as well as Logic Version 6.00 - 2025_07_21. This vulnerability allows remote attackers to execute arbitrary code via the /bh_web_backend component. The issue is exacerbated by the presence of DOM-based Cross-Site Scripting (XSS), which can be exploited to access internal system data and execute JavaScript code.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 25, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/iSee857/ilevia-EVE-X1-Server-CSRF | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | CISA-ADP |
| CWE-352 | Cross-Site Request Forgery (CSRF) | CISA-ADP |
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| ilevia eve x1 server firmware | 4.7.18.0 |
CPE
Remediation
| |
| ilevia eve x1 server | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 30, 2025 | Initial Analysis | [email protected] |
| Nov 25, 2025 | CVE Modified | CISA-ADP |
| Nov 25, 2025 | New CVE Received | [email protected] |