CVE-2025-5310

Dover Fueling Solutions ProGauge MagLink LX Consoles expose an undocumented and unauthenticated target communication framework (TCF) interface on a specific port. Files can be created, deleted, or modified, potentially leading to remote code execution.
Configurations

No configuration.

History

04 Sep 2025, 03:14

Type Values Removed Values Added
References
  • () https://ociocisa.sharepoint.com/teams/JCDC-ProductionOffice/Shared%20Documents/Forms/AllItems.aspx?OR=Teams%2DHL&CT=1736953471669&id=%2Fteams%2FJCDC%2DProductionOffice%2FShared%20Documents%2FPublications%2FICS%20Publishing%2F2025%20ICSAs%2FJUN%2017%2FVU%23285756%20%2D%20Dover%20Fueling%20Solutions%20ProGauge%20MAGLINK%20%2D%20Notice%20%28Draft%29%2Ehtml&viewid=243fd1ea%2Da122%2D4cc0%2Dbe91%2Dd0714ca46b87&parent=%2Fteams%2FJCDC%2DProductionOffice%2FShared%20Documents%2FPublications%2FICS%20Publishing%2F2025%20ICSAs%2FJUN%2017 -
  • () https://www.cisa.gov/news-events/ics-advisories/icsa-25-168-05 -

30 Jun 2025, 18:38

Type Values Removed Values Added
Summary
  • (es) Dover Fueling Solutions ProGauge MagLink LX Consoles exponen una interfaz de framework de comunicación de destino (TCF) no documentada ni autenticada en un puerto específico. Se pueden crear, eliminar o modificar archivos, lo que podría provocar la ejecución remota de código.

27 Jun 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-27 18:15

Updated : 2025-09-04 03:14


NVD link : CVE-2025-5310

Mitre link : CVE-2025-5310

CVE.ORG link : CVE-2025-5310


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function