device firmware for affected versions. An attacker who obtains the
signing key can bypass authentication, gaining complete access to the
system.
Metrics
Affected Vendors & Products
Solution
Dover Fueling Solutions recommends users update their ProGauge MagLink devices to Version 4.20.3 or later for MagLink LX 4 and MagLink LX Plus models. The upgrade can be downloaded from the Dover Fueling Solutions website https://www.doverfuelingsolutions.com/mea/en/products-and-solutions/automatic-tank-gauging/consoles/progauge-maglink-lx-4-console.html .For MagLink LX Ultimate devices, Dover Fueling Solutions recommends users update to version 5.20.3 https://www.doverfuelingsolutions.com/mea/en/products-and-solutions/automatic-tank-gauging/consoles/progauge-maglink-lx-ultimate-console.html or later. Dover Fueling Solutions recommends all users install the software behind a firewall to minimize risk of remote attacks.
Workaround
No workaround given by the vendor.
Thu, 18 Sep 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The secret used for validating authentication tokens is hardcoded in device firmware for affected versions. An attacker who obtains the signing key can bypass authentication, gaining complete access to the system. | |
Title | Dover Fueling Solutions ProGauge MagLink LX4 Devices Use of Hard-coded Cryptographic Key | |
Weaknesses | CWE-321 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-09-18T20:44:04.094Z
Reserved: 2025-08-18T15:32:05.596Z
Link: CVE-2025-54807

No data.

Status : Received
Published: 2025-09-18T21:15:48.493
Modified: 2025-09-18T21:15:48.493
Link: CVE-2025-54807

No data.

No data.