CVE-2025-54807
Deferred
Deferred - Pending Action
BaseFortify
Publication date: 2025-09-18
Last updated on: 2026-06-04
Assigner: ICS-CERT
Description
Description
The secret used for validating authentication tokens is hardcoded in
device firmware for affected versions. An attacker who obtains the
signing key can bypass authentication, gaining complete access to the
system.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| dover_fueling_solutions | progauge_maglink_lx_4_console | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-321 | The product uses a hard-coded, unchangeable cryptographic key. |