Dover Fueling Solutions Vulnerability Allows Attackers to Manipulate Fueling Operations
ID: 79e7a4b9-6746-56da-af4b-000fed2c0cf9
STIX ID: report--79e7a4b9-6746-56da-af4b-000fed2c0cf9
Feed Name: Cyber Press
A critical unauthenticated remote code execution vulnerability (CVE-2025-5310) affects Dover Fueling Solutions ProGauge MagLink LX consoles via an exposed Target Communication Framework interface, enabling attackers to create/modify/delete files, manipulate fueling operations, delete configurations, or deploy malware. Patches are available (v4.20.3+ for LX 4/LX Plus and v5.20.3+ for LX Ultimate); CISA and the vendor recommend immediate patching, network segmentation, hardened remote access, and proactive monitoring. The flaw was discovered by Microsec and disclosed with CISA on 17 June 2025; no public exploits are confirmed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
