Description
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an absolute path traversal vulnerability in get_file_content.php that allows an attacker to read arbitrary files. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
*
Credits
Gjoko Krstic of Zero Science Lab
References
www.ilevia.com/
www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5960.php
www.vulncheck.com/...a-eve-x1-server-absolute-path-traversal