CVE-2025-34184 | Ilevia EVE X1 Server up to 4.7.18.0.eden POST Parameter /ajax/php/login.php passwd os command injection (EUVD-2025-29647)
A vulnerability classified as critical has been found in Ilevia EVE X1 Server up to 4.7.18.0.eden. The affected element is an unknown function of the file /ajax/php/login.php of the component POST Parameter Handler. Performing manipulation of the argument passwd results in os command injection.
This vulnerability is identified as CVE-2025-34184. The attack can be initiated remotely. There is not any exploit available.