CRITICAL🇵🇱 Wersja polska

CVE-2025-30519

CVSS 9.3v4.0pub. 2025-09-18upd. 2026-04-15

Dover Fueling Solutions ProGauge MagLink LX4 Devices have default root credentials that cannot be changed through standard administrative means. An attacker with network access to the device can gain administrative access to the system.

🤖 AI Analysis
How it works

The device contains embedded, default root account credentials that are static and cannot be changed by the administrator through available standard management mechanisms. An attacker with network access to the device can exploit these known credentials to log in with the highest system privileges. Since password change is impossible in normal administrative mode, there is no simple method to eliminate this attack vector without applying the manufacturer's patch.

Impact

An attacker gains full administrative (root) access to the device, enabling arbitrary configuration manipulation, sensitive data extraction, and potential disruption of fuel infrastructure operations served by the device.

Mitigation & patch

Apply patches available from the manufacturer according to the references (CISA ICS advisory ICSA-25-261-07 and Dover Fueling Solutions information). Until patches are applied, restrict network access to devices through network segmentation, firewalls, and other access control mechanisms to ensure devices are not directly accessible from untrusted networks.

Who is affected

Dover Fueling Solutions ProGauge MagLink LX4 devices — specific firmware versions indicated in manufacturer references (CISA advisory ICSA-25-261-07).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References