CVE-2025-5310

Dover Fueling Solutions ProGauge MagLink LX Consoles Missing Authentication for Critical Function

Description

Dover Fueling Solutions ProGauge MagLink LX Consoles expose an undocumented and unauthenticated target communication framework (TCF) interface on a specific port. Files can be created, deleted, or modified, potentially leading to remote code execution.

Remediation

Solution:

  • Dover Fueling Solutions recommends users update their ProGauge MagLink devices to Version 4.20.3 or later for MagLink LX 4 and MagLink LX Plus models. The upgrade can be downloaded from the Dover Fueling Solutions website https://ociocisa.sharepoint.com/teams/JCDC-ProductionOffice/Shared%20Documents/Forms/AllItems.aspx .For MagLink LX Ultimate devices, Dover Fueling Solutions recommends users update to version 5.20.3 https://ociocisa.sharepoint.com/teams/JCDC-ProductionOffice/Shared%20Documents/Forms/AllItems.aspx  or later.

Category

9.3
CVSS
Severity: Critical
CVSS 4.0 •
CVSS 3.1 •
EPSS 0.25%
Affected: Dover Fueling Solutions ProGauge MagLink LX 4
Affected: Dover Fueling Solutions ProGauge MagLink LX Plus
Affected: Dover Fueling Solutions ProGauge MagLink LX Ultimate
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2025-5310?
CVE-2025-5310 has been scored as a critical severity vulnerability.
How to fix CVE-2025-5310?
To fix CVE-2025-5310: Dover Fueling Solutions recommends users update their ProGauge MagLink devices to Version 4.20.3 or later for MagLink LX 4 and MagLink LX Plus models. The upgrade can be downloaded from the Dover Fueling Solutions website https://ociocisa.sharepoint.com/teams/JCDC-ProductionOffice/Shared%20Documents/Forms/AllItems.aspx .For MagLink LX Ultimate devices, Dover Fueling Solutions recommends users update to version 5.20.3 https://ociocisa.sharepoint.com/teams/JCDC-ProductionOffice/Shared%20Documents/Forms/AllItems.aspx  or later.
Is CVE-2025-5310 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2025-5310 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2025-5310?
CVE-2025-5310 affects Dover Fueling Solutions ProGauge MagLink LX 4, Dover Fueling Solutions ProGauge MagLink LX Plus, Dover Fueling Solutions ProGauge MagLink LX Ultimate.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.