CVE-2025-34516: Ilevia EVE X1 Server 4.7.18.0.eden Use of Default Credentials
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unauthenticated attacker to obtain remote access. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.
Security readout for executives and security teams
Plain-English summary
CVE-2025-34516 affects Ilevia EVE X1 Server firmware up to 4.7.18.0.eden. The device can be remotely accessed using default credentials, with no prior authentication required. The source bundle says Ilevia declined to service the issue and recommends not exposing port 8080 to the internet.
Executive priority
Treat this as urgent for any exposed building automation or smart-home control environment. The vendor has not provided a serviced fix in the source bundle, so exposure reduction and access control are the primary business actions.
Technical view
The issue is CWE-1392, use of default credentials, in Ilevia EVE X1 Server. CVSS v4.0 is 9.3: network reachable, low complexity, no privileges, no user interaction, with high confidentiality, integrity, and availability impact on the vulnerable system.
Likely exposure
Highest risk is internet-exposed EVE X1 Server deployments, especially where port 8080 is reachable. Internal-only systems still matter if default credentials are present and accessible to untrusted network segments.
Exploitation context
The CVE is not listed as KEV in the source bundle. A public technical/exploit-tagged reference exists, but the provided evidence does not confirm active in-the-wild exploitation.
Researcher notes
Evidence supports unauthenticated remote access via default credentials, but the bundle does not provide a vendor patch, fixed version, or confirmed exploitation telemetry. Avoid assuming affected CPE coverage because the affected entry lacks specific CPE identifiers.
Mitigation direction
Do not expose port 8080 to the internet, per Ilevia’s recommendation.
Place affected systems behind VPN, firewall, or trusted management networks.
Review and remove default credentials where the product permits it.
Check Ilevia guidance for current operational recommendations.
Monitor affected systems for unauthorized remote access indicators.
Validation and detection
Inventory Ilevia EVE X1 Server deployments and firmware versions.
Confirm whether firmware is 4.7.18.0.eden or earlier.
Verify port 8080 is not reachable from the public internet.
Review access logs for unexpected remote administration activity.
Confirm credential configuration with system owners.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-1392: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
4Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: yesTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-1392 · source CWE mapping
Use of Default Credentials
Use of Default Credentials represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.