Unrated severityNVD Advisory· Published Nov 20, 2025· Updated Nov 21, 2025
CVE-2025-60737
CVE-2025-60737
Description
Cross Site Scripting vulnerability in Ilevia EVE X1 Server Firmware Version<= 4.7.18.0.eden:Logic Version<=6.00 - 2025_07_21 allows a remote attacker to execute arbitrary code via the /index.php component
Affected products
2- Ilevia/EVE X1 Server Firmwaredescription
- Range: firmware <= 4.7.18.0.eden, Logic <=6.00 (2025_07_21)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
News mentions
0No linked articles in our index yet.