Junglewise Threat Intelligence

CVE-2025-34186: Ilevia EVE X1/X5 Server authentication bypass via command injection

CVE-2025-34186 · Severity: critical · CVSS 9.8 · Published 2025-09-16

Executive brief

Ilevia EVE X1 and X5 servers, which are used to manage smart building automation systems like lighting and climate control, contain a critical security flaw in their login process. An attacker can bypass the password requirement by sending specially crafted characters that confuse the system's internal authentication check. If exploited, a remote attacker could gain full control over the building's automated systems, potentially leading to unauthorized access to physical locks, cameras, and environmental controls.

Technical details

The vulnerability exists within the authentication mechanism of the Ilevia EVE X1/X5 Server. The application passes unsanitized user input directly to a system() call to perform authentication tasks, leading to OS command injection (CWE-78). Furthermore, the binary logic incorrectly interprets any non-zero exit code from the system() call as a successful authentication event. A remote, unauthenticated attacker can exploit this by injecting shell metacharacters that cause the command to fail or return a specific exit status, thereby bypassing the authentication check entirely. This allows for full administrative access to the server's management interface and underlying building automation protocols.

Affected products

  • Ilevia EVE X1 Server ≤ 4.7.18.0.eden
  • Ilevia EVE X5 Server ≤ 4.7.18.0.eden

Timeline

  • 2025-09-16: advisory: Initial disclosure by VulnCheck and Zero Science Lab
  • 2025-09-16: disclosed

References