Description
Dover Fueling Solutions ProGauge MagLink LX Consoles expose an undocumented and unauthenticated target communication framework (TCF) interface on a specific port. Files can be created, deleted, or modified, potentially leading to remote code execution.
Problem types
Product status
Any version before 4.20.3
Any version before 4.20.3
Any version before 5.20.3
Credits
Souvik Kandar of Microsec reported this vulnerability to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-168-05
ociocisa.sharepoint.com/...lishing%2F2025%20ICSAs%2FJUN%2017