Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gqwg-v25f-563v

Опубликовано: 25 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.6

Описание

Cross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before, Logic Version v6.00 - 2025_07_21 allows a remote attacker to execute arbitrary code via the /bh_web_backend component

Cross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before, Logic Version v6.00 - 2025_07_21 allows a remote attacker to execute arbitrary code via the /bh_web_backend component

EPSS

Процентиль: 30%
0.00114
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 9.6
nvd
2 месяца назад

Cross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before, Logic Version v6.00 - 2025_07_21 allows a remote attacker to execute arbitrary code via the /bh_web_backend component

EPSS

Процентиль: 30%
0.00114
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-79