CVE-2025-55068
8.2Dover Fueling Solutions · ProGauge MagLink LX Series
Dover Fueling Solutions ProGauge MagLink LX devices are vulnerable to a denial-of-service condition due to improper handling of Unix time values, which can be triggered by manipulating system time.
Executive summary
Dover Fueling Solutions ProGauge MagLink LX devices contain a critical integer overflow vulnerability that allows unauthenticated attackers to trigger a denial-of-service condition.
Vulnerability
This vulnerability, classified as CWE-190 (Integer Overflow or Wraparound), occurs because the device fails to properly process Unix time values. An unauthenticated attacker can manually manipulate the system time to trigger this flaw, resulting in authentication failures and a total denial-of-service condition for the affected console.
Business impact
The exploitation of this vulnerability can lead to significant operational disruption as the ProGauge MagLink consoles are responsible for critical fuel tank monitoring. A denial-of-service condition could render these systems unresponsive, preventing fuel inventory tracking and safety alerting. With a CVSS score of 8.2, the risk is classified as High, reflecting the potential for complete loss of availability in industrial control environments.
Remediation
Immediate Action: Update ProGauge MagLink LX 4 and LX Plus devices to version 4.20.3, and update MagLink LX Ultimate devices to version 5.20.3, available via the official Dover Fueling Solutions website.
Proactive Monitoring: Monitor system logs for unexpected time synchronization changes or frequent reboots of the MagLink console, which may indicate attempted exploitation.
Compensating Controls: Restrict network access to the management interface of these devices to authorized personnel only using hardware firewalls or isolated VLANs to prevent unauthorized time configuration changes.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit available.
Analyst recommendation
Given the critical nature of fuel monitoring systems and the ease with which an unauthenticated attacker can trigger a denial-of-service, administrators must prioritize these firmware updates. Ensure that all affected ProGauge MagLink LX consoles are upgraded to their respective patched versions as soon as possible to maintain system availability and security integrity.
More Dover Fueling Solutions CVEs
Sources
Originally found and disclosed by Pedro Umbelino of Bitsight TRACE reported these vulnerabilities to CISA., per the CVE Program record.