CVE-2025-30519
9.8Dover Fueling Solutions · ProGauge MagLink
Dover Fueling Solutions ProGauge MagLink devices contain hardcoded default root credentials that cannot be changed, allowing unauthenticated remote administrative access.
Executive summary
Dover Fueling Solutions ProGauge MagLink devices are vulnerable to unauthorized administrative access due to unchangeable default root credentials, posing a critical risk of full system compromise.
Vulnerability
This vulnerability involves the use of hardcoded default credentials (CWE-1391) that cannot be modified by administrators. An unauthenticated attacker with network access to the device can leverage these credentials to gain full administrative control over the system.
Business impact
The presence of unchangeable default credentials represents a severe security flaw, warranting the 9.8 CVSS score. Successful exploitation grants an attacker complete control over the tank gauging system, potentially leading to unauthorized manipulation of fuel data, disruption of facility operations, or the lateral movement of threats into internal industrial control networks.
Remediation
Immediate Action: Update ProGauge MagLink LX 4 and LX Plus devices to version 4.20.3 or later, and update ProGauge MagLink LX Ultimate devices to version 5.20.3 or later.
Proactive Monitoring: Monitor network traffic for unauthorized access attempts directed at management ports and review system logs for suspicious authentication events involving administrative accounts.
Compensating Controls: Restrict network access to the devices by placing them behind a firewall or within an isolated management VLAN to ensure they are not reachable from the public internet or untrusted network segments.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical severity of this vulnerability and the ease with which an attacker can gain administrative access, immediate patching is required. Organizations utilizing these devices must prioritize the firmware update to remove the hardcoded credentials and prevent potential unauthorized control of their fueling infrastructure.
More Dover Fueling Solutions CVEs
Sources
Originally found and disclosed by Pedro Umbelino of Bitsight TRACE reported these vulnerabilities to CISA., per the CVE Program record.