CVE-2025-34187
Last modified
CVE-2025-34187 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a misconfiguration in the sudoers file that allows passwordless execution of certain Bash scripts. If these scripts are writable by web-facing users or accessible via command injection, attackers can replace them with malicious payloads. EPSS estimates a 3.19% chance of exploitation in the next 30 days.
Description
Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a misconfiguration in the sudoers file that allows passwordless execution of certain Bash scripts. If these scripts are writable by web-facing users or accessible via command injection, attackers can replace them with malicious payloads. Execution with sudo grants full root access, resulting in remote privilege escalation and potential system compromise.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ilevia | Eve X1 Server Firmware | <= 4.7.18.0 |
References
- https://packetstorm.news/files/id/209226/Exploit, Permissions Required, Third Party Advisory
- https://www.ilevia.com/Product
- https://www.vulncheck.com/advisories/ilevia-eve-x1-x5-server-reverse-rootshellThird Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5959.phpExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-34187?
How severe is CVE-2025-34187?
How do I fix CVE-2025-34187?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-34181NetSupport Manager < 14.12.0001 contains an arbitrary file w…8.7
- CVE-2025-34182In Deciso OPNsense before 25.7.4, when creating an "Interfac…5.1
- CVE-2025-34183Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vuln…7.5
- CVE-2025-34184Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains an una…9.8
- CVE-2025-34185Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a pre-…7.5
- CVE-2025-34186Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a v…9.8
- CVE-2025-34188Vasion Print (formerly PrinterLogic) Virtual Appliance Host …7.8
- CVE-2025-34189Vasion Print (formerly PrinterLogic) Virtual Appliance Host …7.8
- CVE-2025-3419The Event Manager, Events Calendar, Tickets, Registrations –…7.5
- CVE-2025-34190Vasion Print (formerly PrinterLogic) Virtual Appliance Host …7.8
- CVE-2025-34191Vasion Print (formerly PrinterLogic) Virtual Appliance Host …8.4
- CVE-2025-34192Vasion Print (formerly PrinterLogic) Virtual Appliance Host …9.8
Are you affected by CVE-2025-34187?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
