Title: Illevia EVE X1 Server 4.7.18.0.eden Neuro-Core Unauth Code Invasion Type: Local/Remote Impact: System Access, DoS Release Date: 31.07.2025 Summary: The EVE X1 server suffers from an unauthenticated OS command injection vulnerability, allowing arbitrary shell commands to be injected and executed through the 'passwd' HTTP-POST parameter in /api/php/login.php script. Affected Version: References: - [1] https://packetstormsecurity.news/files/id207717/ - [2] https://www.vulncheck.com/advisories/illevia-eve-x1-server-neuro-code-unauth-code-injection - [3] https://www.cve.org/CVERecord?id=CVE-2025-34184