CVE 9.8 CRITICAL

Dover Fueling Solutions ProGauge MagLink LX4 Devices Use of Hard-coded Cryptographic Key_CVE-2025-54807

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The secret used for validating authentication tokens is hardcoded in
device firmware for affected versions. An attacker who obtains the
signing key can bypass authentication, gaining complete access to the
system.

Basic Information

ID CVE-2025-54807
Source icscert
Published Sep 18, 2025 at 20:44

Affected Product

Vendor Dover Fueling Solutions
Product ProGauge MagLink LX 4
Affected Versions Dover Fueling Solutions ProGauge MagLink LX 4 0
Dover Fueling Solutions ProGauge MagLink LX Plus 0
Dover Fueling Solutions ProGauge MagLink LX Ultimate 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.