CVE-2025-30519
BaseFortify
Publication date: 2025-09-18
Last updated on: 2025-09-19
Assigner: ICS-CERT
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| dover_fueling_solutions | progage_maglink_lx4 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1391 | The product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in Dover Fueling Solutions ProGauge MagLink LX4 Devices, which have default root credentials that cannot be changed through standard administrative methods. This means that anyone with network access to the device can use these default credentials to gain full administrative control over the system.
How can this vulnerability impact me? :
An attacker exploiting this vulnerability can gain administrative access to the affected device remotely without needing any prior privileges or user interaction. This can lead to unauthorized control, potential manipulation of device functions, disruption of operations, and compromise of the system's integrity and availability.