CVE-2025-54807

CRITICAL

Device Firmware <unknown - Auth Bypass

Title source: llm
STIX 2.1

Description

The secret used for validating authentication tokens is hardcoded in device firmware for affected versions. An attacker who obtains the signing key can bypass authentication, gaining complete access to the system.

Scores

CVSS v3 9.8
EPSS 0.0008
EPSS Percentile 24.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-321
Status published
Products (3)
Dover Fueling Solutions/ProGauge MagLink LX 4 < 4.20.3
Dover Fueling Solutions/ProGauge MagLink LX Plus < 4.20.3
Dover Fueling Solutions/ProGauge MagLink LX Ultimate < 5.20.3
Published Sep 18, 2025
Tracked Since Feb 18, 2026