CVE-2025-58428: Veeder-Root TLS4B Automatic Tank Gauge System

Critical severity, CVSS 9.9. EPSS: 1.4% chance of exploitation in the next 30 days.

The TLS4B ATG system's SOAP-based interface is vulnerable due to its accessibility through the web services handler. This vulnerability enables remote attackers with valid credentials to execute system-level commands on the underlying Linux system. This could allow the attacker to achieve remote command execution, full shell access, and potential lateral movement within the network.

Affected products

  • Veeder-Root TLS4B Automatic Tank Gauge System: before 11.A (fixed in 11.A)

Published 2025-10-23. Last modified 2026-10-08.