CVE-2025-5310
BaseFortify
Publication date: 2025-06-27
Last updated on: 2025-09-04
Assigner: ICS-CERT
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves Dover Fueling Solutions ProGauge MagLink LX Consoles exposing an undocumented and unauthenticated target communication framework (TCF) interface on a specific port. This exposure allows an attacker to create, delete, or modify files remotely, which can potentially lead to remote code execution on the affected device.
How can this vulnerability impact me? :
The vulnerability can have severe impacts including unauthorized remote code execution, which may allow attackers to take control of the affected system, disrupt operations, manipulate data, or cause other malicious activities without requiring authentication.