device firmware for affected versions. An attacker who obtains the
signing key can bypass authentication, gaining complete access to the
system.
Metrics
Affected Vendors & Products
Source | ID | Title |
---|---|---|
![]() |
EUVD-2025-30193 | The secret used for validating authentication tokens is hardcoded in device firmware for affected versions. An attacker who obtains the signing key can bypass authentication, gaining complete access to the system. |
Solution
Dover Fueling Solutions recommends users update their ProGauge MagLink devices to Version 4.20.3 or later for MagLink LX 4 and MagLink LX Plus models. The upgrade can be downloaded from the Dover Fueling Solutions website https://www.doverfuelingsolutions.com/mea/en/products-and-solutions/automatic-tank-gauging/consoles/progauge-maglink-lx-4-console.html .For MagLink LX Ultimate devices, Dover Fueling Solutions recommends users update to version 5.20.3 https://www.doverfuelingsolutions.com/mea/en/products-and-solutions/automatic-tank-gauging/consoles/progauge-maglink-lx-ultimate-console.html or later. Dover Fueling Solutions recommends all users install the software behind a firewall to minimize risk of remote attacks.
Workaround
No workaround given by the vendor.
Fri, 19 Sep 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 19 Sep 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Doverfuelingsolutions
Doverfuelingsolutions progauge Maglink Lx Console |
|
Vendors & Products |
Doverfuelingsolutions
Doverfuelingsolutions progauge Maglink Lx Console |
Thu, 18 Sep 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The secret used for validating authentication tokens is hardcoded in device firmware for affected versions. An attacker who obtains the signing key can bypass authentication, gaining complete access to the system. | |
Title | Dover Fueling Solutions ProGauge MagLink LX4 Devices Use of Hard-coded Cryptographic Key | |
Weaknesses | CWE-321 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-09-19T13:06:19.294Z
Reserved: 2025-08-18T15:32:05.596Z
Link: CVE-2025-54807

Updated: 2025-09-19T13:06:14.665Z

Status : Awaiting Analysis
Published: 2025-09-18T21:15:48.493
Modified: 2025-09-19T16:00:27.847
Link: CVE-2025-54807

No data.

Updated: 2025-09-19T09:35:17Z