CVE-2025-5310: Dover Fueling Solutions Progauge Maglink Lx 4
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
Dover Fueling Solutions ProGauge MagLink LX Consoles expose an undocumented and unauthenticated target communication framework (TCF) interface on a specific port. Files can be created, deleted, or modified, potentially leading to remote code execution.
Affected products
- Dover Fueling Solutions Progauge Maglink Lx 4: before 4.20.3 (fixed in 4.20.3)
- Dover Fueling Solutions Progauge Maglink Lx Plus: before 4.20.3 (fixed in 4.20.3)
- Dover Fueling Solutions Progauge Maglink Lx Ultimate: before 5.20.3 (fixed in 5.20.3)
Published 2025-06-27. Last modified 2026-06-17.