Metrics
Affected Vendors & Products
Tue, 09 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Dec 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ilevia
Ilevia eve X1 Server |
|
| Vendors & Products |
Ilevia
Ilevia eve X1 Server |
Mon, 08 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in Ilevia EVE X1 Server up to 4.6.5.0.eden. Impacted is an unknown function of the file /ajax/php/leaf_search.php. This manipulation of the argument line causes command injection. The attack can be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is considered difficult. The exploit has been publicly disclosed and may be utilized. Upgrading the affected component is recommended. The vendor confirms the issue and recommends: "We already know that issue and on most devices are already solved, also it’s not needed to open the port to outside world so we advised our customer to close it". | |
| Title | Ilevia EVE X1 Server leaf_search.php command injection | |
| Weaknesses | CWE-74 CWE-77 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-12-08T21:32:08.167Z
Updated: 2025-12-09T16:05:40.812Z
Reserved: 2025-12-08T16:23:09.183Z
Link: CVE-2025-14276
Updated: 2025-12-09T14:38:15.927Z
Status : Awaiting Analysis
Published: 2025-12-08T22:15:50.933
Modified: 2025-12-09T18:37:33.427
Link: CVE-2025-14276
No data.