Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden...
        
  Moderate severity
        
          Unreviewed
      
        Published
          Oct 16, 2025 
          to the GitHub Advisory Database
          •
          Updated Oct 23, 2025 
      
  
Description
        Published by the National Vulnerability Database
      Oct 16, 2025 
    
  
        Published to the GitHub Advisory Database
      Oct 16, 2025 
    
  
        Last updated
      Oct 23, 2025 
    
  
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a reflected cross-site scripting (XSS) vulnerability in index.php that allows an unauthenticated attacker to execute arbitrary code. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.
References