Description
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax/php/login.php script. Remote attackers can execute arbitrary system commands by injecting payloads into the 'passwd' HTTP POST parameter, leading to full system compromise or denial of service.
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
* (custom)
Credits
Gjoko Krstic of Zero Science Lab
References
www.ilevia.com/
www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5956.php
packetstorm.news/files/id/207717/
www.vulncheck.com/...server-neuro-code-unauth-code-injection