Cyber Posture

CVE-2025-34516

CriticalPublic PoC

Published: 16 October 2025

Published
16 October 2025
Modified
03 November 2025
KEV Added
Patch
CVSS Score 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0017 38.4th percentile
Risk Priority 20 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2025-34516 is a critical-severity Use of Default Credentials (CWE-1392) vulnerability in Ilevia Eve X1 Server Firmware. Its CVSS base score is 9.8 (Critical).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 38.4th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

The strongest mitigations our analysis identified are NIST 800-53 AC-17 (Remote Access) and IA-5 (Authenticator Management).

Threat & Defense at a Glance

What attackers do: exploitation maps to Exploit Public-Facing Application (T1190) and 1 other technique. What defenders deploy: see the NIST 800-53 controls recommended below.
Threat & Defense Details

Mitigating Controls (NIST 800-53 r5)AI

prevent

IA-5 requires changing default authenticators prior to first use, directly eliminating the use of default credentials that enable unauthenticated remote access.

prevent

SC-7 enforces boundary protection to monitor and control communications at external interfaces, preventing network access to the vulnerable port 8080 as recommended by the vendor.

prevent

AC-17 establishes usage restrictions, authorization, and monitoring for remote access, mitigating exploitation of the default credentials vulnerability over remote connections.

MITRE ATT&CK Enterprise TechniquesAI

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
T1078.001 Default Accounts Stealth
Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
Why these techniques?

Default credentials vulnerability in public-facing server (port 8080) enables initial access via T1190 (Exploit Public-Facing Application) and T1078.001 (Default Accounts).

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

NVD Description

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unauthenticated attacker to obtain remote access. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to…

more

the internet.

Deeper analysisAI

CVE-2025-34516 is a use of default credentials vulnerability (CWE-1392) in Ilevia EVE X1 Server firmware versions up to and including 4.7.18.0.eden. This issue allows an unauthenticated attacker to gain remote access to affected devices, earning a critical CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Any unauthenticated attacker with network access to the server, particularly port 8080, can exploit this vulnerability with low complexity and no privileges or user interaction required. Successful exploitation provides remote access, enabling high-impact compromise of confidentiality, integrity, and availability, such as executing arbitrary commands, modifying configurations, or disrupting device operations.

Advisories from sources including VulnCheck and Zero Science Lab indicate that Ilevia has declined to service or patch this vulnerability. The vendor recommends that customers avoid exposing port 8080 to the internet as the sole mitigation strategy.

Details

CWE(s)

Affected Products

ilevia
eve x1 server firmware
≤ 4.7.18.0

CVEs Like This One

CVE-2025-60738Same product: Ilevia Eve X1 Server
CVE-2025-34515Same product: Ilevia Eve X1 Server
CVE-2025-34184Same product: Ilevia Eve X1 Server
CVE-2025-60739Same product: Ilevia Eve X1 Server
CVE-2025-34186Same product: Ilevia Eve X1 Server
CVE-2025-34513Same product: Ilevia Eve X1 Server
CVE-2025-34514Same product: Ilevia Eve X1 Server
CVE-2025-34187Same product: Ilevia Eve X1 Server
CVE-2026-1972Shared CWE-1392
CVE-2025-0482Shared CWE-1392

References