Junglewise Threat Intelligence

CVE-2025-54807: Dover Fueling Solutions ProGauge MagLink LX hardcoded auth secret

CVE-2025-54807 · Severity: critical · CVSS 9.8 · Published 2025-09-18

Executive brief

Dover Fueling Solutions ProGauge MagLink LX devices are consoles used to monitor fuel and water levels in storage tanks, commonly used at gas stations and industrial sites. A security flaw exists where the secret key used to verify user logins is permanently hardcoded into the device's software. An attacker who knows this key can bypass all security checks to gain full administrative control over the tank monitoring system, potentially leading to data theft or operational disruption.

Technical details

The vulnerability (CWE-321) exists because the secret key used for validating authentication tokens is hardcoded within the device firmware. This allows a remote, unauthenticated attacker to generate valid authentication tokens by using the known signing key. Successful exploitation grants the attacker complete administrative access to the system. The flaw affects ProGauge MagLink LX 4 and LX Plus (versions prior to 4.20.3) and LX Ultimate (versions prior to 5.20.3). Users are advised to update to versions 4.20.3 or 5.20.3 respectively to remediate the issue.

Affected products

  • Dover Fueling Solutions ProGauge MagLink LX 4 prior to 4.20.3
  • Dover Fueling Solutions ProGauge MagLink LX Plus prior to 4.20.3
  • Dover Fueling Solutions ProGauge MagLink LX Ultimate prior to 5.20.3

Timeline

  • 2025-09-18: disclosed
  • 2025-09-18: advisory: CISA ICSA-25-261-07 published

References