Ilevia EVE X1 Server Command Injection Vulnerability in leaf_search.php
Vulnerability
A command injection vulnerability has been identified in Ilevia EVE X1 Server versions prior to 4.6.5.0.eden. The issue resides in an unknown function of the file /ajax/php/leaf_search.php, where manipulation of the 'line' argument allows for command injection. This vulnerability can be exploited remotely, although it requires a high level of complexity. The exploit has been publicly disclosed and is available for use.
Impact
Exploitation of this vulnerability allows for remote command execution on the affected server.
Reproduction
To reproduce this vulnerability, send a POST request to /ajax/php/leaf_search.php with the 'line' parameter manipulated to include a command, such as 'whoami', using a payload that directs the output to a file on the server.
Remediation
Users are advised to upgrade to version 4.6.5.0.eden or later. The vendor recommends closing the port to the outside world, as the issue has been resolved on most devices.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
