Description

Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a pre-authentication file disclosure vulnerability via the 'db_log' POST parameter. Remote attackers can retrieve arbitrary files from the server, exposing sensitive system information and credentials.

INFO

Published Date :

2025-09-16T19:44:26.532Z

Last Modified :

2026-03-23T15:43:43.929Z

Source :

VulnCheck
AFFECTED PRODUCTS

The following products are affected by CVE-2025-34185 vulnerability.

Vendors Products
Ilevia
  • Eve X1 Server
  • Eve X1 Server Firmware

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact