Default Credentials Vulnerability in Dover Fueling Solutions ProGauge MagLink LX4 Devices
CVE-2025-30519
9.3CRITICAL
What is CVE-2025-30519?
Dover Fueling Solutions ProGauge MagLink LX4 devices are susceptible to an issue where default root credentials are hard-coded and cannot be modified through conventional administrative methods. This flaw allows an attacker with network access to exploit the vulnerability and gain unauthorized administrative control over the system. Organizations using these devices must take proactive measures to mitigate potential risks associated with this security oversight.
Affected Version(s)
ProGauge MagLink LX 4 0 < 4.20.3
ProGauge MagLink LX Plus 0 < 4.20.3
ProGauge MagLink LX Ultimate 0 < 5.20.3
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Pedro Umbelino of Bitsight TRACE reported these vulnerabilities to CISA.