Ilevia EVE X1 Server Insecure Hashing Algorithm Vulnerability

Vulnerability

A vulnerability exists in Ilevia EVE X1 Server firmware versions through 4.7.18.0.eden, where passwords are stored using the MD5 hashing algorithm without a per-password salt. This unsalted hash allows attackers to efficiently execute offline dictionary, rainbow-table, or brute-force attacks to recover original passwords. Ilevia has chosen not to address this vulnerability and advises customers to avoid exposing port 8080 to the internet.

Impact

Exploitation of this vulnerability allows for the recovery of original passwords from the password database, due to the use of unsalted MD5 hashes.

Added: Oct 16, 2025, 6:28 PM
Updated: Oct 16, 2025, 6:28 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.2
remediation
0.0
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.