CVE-2025-34183

Severity CVSS v4.0:
CRITICAL
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
16/09/2025
Last modified:
25/09/2025

Description

Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attackers to retrieve plaintext credentials from exposed .log files. This flaw enables full authentication bypass and system compromise through credential reuse.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ilevia:eve_x1_server_firmware:*:*:*:*:*:*:*:* 4.7.18.0 (including)
cpe:2.3:h:ilevia:eve_x1_server:-:*:*:*:*:*:*:*