关键信息 漏洞名称: Ilevia EVE X1 Server 4.7.18.0.eden Authenticated Command Injection 严重性: HIGH 日期: October 16, 2025 影响版本: EVE X1 Server <= 4.7.18.0.eden CVE编号: CVE-2025-34514 CWE编号: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVSS评分: 8.7 CVSS V4向量: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VL:H/VA:H/SC:N/SE:N/SA:N 参考链接: - Ilevia Product Site 发现者: Gjoko Krstic of Zero Science Lab 描述: Ilevia EVE X1 Server firmware versions <= 4.7.18.0.eden contain authenticated OS command injection vulnerabilities in multiple web-accessible PHP scripts that call exec() and allow an authenticated attacker to execute arbitrary commands. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.