Dover Fueling Solutions ProGauge MagLink LX4 Devices have default root credentials that cannot be changed through standard administrative means. An attacker with network access to the device can gain administrative access to the system.
The device contains embedded, default root account credentials that are static and cannot be changed by the administrator through available standard management mechanisms. An attacker with network access to the device can exploit these known credentials to log in with the highest system privileges. Since password change is impossible in normal administrative mode, there is no simple method to eliminate this attack vector without applying the manufacturer's patch.
An attacker gains full administrative (root) access to the device, enabling arbitrary configuration manipulation, sensitive data extraction, and potential disruption of fuel infrastructure operations served by the device.
Apply patches available from the manufacturer according to the references (CISA ICS advisory ICSA-25-261-07 and Dover Fueling Solutions information). Until patches are applied, restrict network access to devices through network segmentation, firewalls, and other access control mechanisms to ensure devices are not directly accessible from untrusted networks.
Dover Fueling Solutions ProGauge MagLink LX4 devices — specific firmware versions indicated in manufacturer references (CISA advisory ICSA-25-261-07).
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X