Ilevia EVE X1 Server Command Injection Vulnerability in leaf_search.php

Vulnerability

A command injection vulnerability has been identified in Ilevia EVE X1 Server versions prior to 4.6.5.0.eden. The issue resides in an unknown function of the file /ajax/php/leaf_search.php, where manipulation of the 'line' argument allows for command injection. This vulnerability can be exploited remotely, although it requires a high level of complexity. The exploit has been publicly disclosed and is available for use.

Impact

Exploitation of this vulnerability allows for remote command execution on the affected server.

Reproduction

To reproduce this vulnerability, send a POST request to /ajax/php/leaf_search.php with the 'line' parameter manipulated to include a command, such as 'whoami', using a payload that directs the output to a file on the server.

Remediation

Users are advised to upgrade to version 4.6.5.0.eden or later. The vendor recommends closing the port to the outside world, as the issue has been resolved on most devices.

Added: Dec 8, 2025, 10:24 PM
Updated: Dec 8, 2025, 10:24 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
1.4
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.