External risk intelligence

Ilevia EVE X1 Server OS Command Injection

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2025-34513

The vulnerability affects an EVE X1 Server, which is typically deployed as a management or control gateway for building automation. While the vendor advises against exposing the specific service port to the internet, these devices are commonly deployed as network-accessible portals or edge interfaces, making public internet reachability a common deployment pattern for this class of equipment.

OS Command Injection

Ilevia Eve X1 Server Firmware

4.7.18.0 and earlier

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in Ilevia EVE X1 Server firmware. An unauthenticated attacker could exploit this issue to execute arbitrary code, potentially impacting the operational integrity of affected systems. The vendor has declined to service this vulnerability and recommends restricting access to a specific network port.

  • Unauthenticated code execution in server firmware.
  • Impacts building automation systems.
  • Confirm relevance and assess exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability by reaching the `mbus_build_from_csv.php` script on the Ilevia EVE X1 Server. By sending specially crafted input to this script, which is exposed via port 8080, an attacker can inject and execute arbitrary operating system commands on the server.

  • Exposed to the network.
  • Specially crafted input to `mbus_build_from_csv.php`.
  • Arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in the Ilevia EVE X1 Server firmware could allow an unauthenticated attacker to execute arbitrary code when the affected port is accessible. This could potentially impact the integrity and availability of the server's operations.

  • Server operations and integrity.
  • Unauthenticated code execution.
  • Disruption of building automation.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Ilevia EVE X1 Server firmware vulnerability requires immediate attention from teams managing building automation and industrial control systems. The first step is to identify all instances of the affected firmware, verify if the vulnerable port is exposed externally, and confirm business criticality before planning remediation.

  • Identify all EVE X1 Server instances.
  • Verify port 8080 exposure and criticality.
  • Plan remediation based on confirmed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Ilevia EVE X1 Server and why is it used?

The Ilevia EVE X1 Server is hardware firmware designed for building automation systems. It functions as a centralized gateway or interface to manage, control, and monitor various smart building components, such as lighting, climate control, or security systems, essentially acting as the operational hub for these connected environments.

What does the CVE-2025-34513 vulnerability mean?

CVE-2025-34513 involves a weakness classified as OS Command Injection. In plain terms, this means the software does not properly filter data sent to a specific script, allowing an attacker to inject their own operating system commands. Because the system runs these commands as if they were legitimate instructions, it can lead to full, unauthorized control over the server.

How does an attacker trigger this command injection bug?

An attacker triggers the vulnerability by sending specially crafted input to the mbus_build_from_csv.php script. This script acts as the entry point for the malicious commands. It is important to note that the vulnerability is not triggered by standard, expected system traffic; it specifically requires the transmission of specific, malicious data strings that the software is not programmed to handle.

How does Halo Surface Signal determine if I should care about this?

Halo Surface Signal flags this as relevant because the EVE X1 Server often acts as a network-accessible portal for building management. Even if the device is meant to be internal, these gateways are frequently deployed with network reachability. If your device is reachable over the network on port 8080, Halo identifies it as a higher-risk target for this specific vulnerability.

What should I do if I am running this technology?

Since there is no vendor patch, your primary goal is to isolate the server. Start by identifying all instances of the EVE X1 Server in your environment. Next, verify if port 8080 is accessible from outside your local network and restrict this access immediately. Assess the business importance of each device to determine if additional network-level defenses or segmentation are necessary to maintain operations.

References