Dover Fueling Solutions maintains a focused line of fueling-station management and console products, primarily the ProGauge MagLink series, that control critical infrastructure for petroleum distribution and fleet operations. Vulnerabilities affecting this vendor's products skew strongly toward critical-severity outcomes and recur through authentication and access-control weaknesses—including authentication bypass via alternate channels, command injection, and path traversal—that are characteristic of industrial control and point-of-sale systems where direct operator access and input validation are core security boundaries. Defenders should inventory these consoles and prioritize patching, since the vendor's device footprint operates in high-availability environments where remediation windows may be constrained; live severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Doverfuelingsolutions over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-45066CRITICAL A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE IP
sub-menu can allow a remote attacker to inject arbitrary commands. | Sep 25, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-43693CRITICAL A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE
UTILITY sub-menu can allow a remote attacker to inject arbitrary
commands. | Sep 25, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-43692CRITICAL An attacker can directly request the ProGauge MAGLINK LX CONSOLE
resource sub page with full privileges by requesting the URL directly. | Sep 25, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-43423CRITICAL The web application for ProGauge MAGLINK LX4 CONSOLE contains an
administrative-level user account with a password that cannot be
changed. | Sep 25, 2024 | 9.8 | 28 | NO | NO |
CVE-2023-36497HIGH Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3
could allow a guest user to elevate to admin privileges. | Sep 11, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-41256CRITICAL
Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3 are vulnerable to authentication bypass that could allow | Sep 11, 2023 | 9.1 | 26 | NO | NO |
CVE-2024-45373HIGH Once logged in to ProGauge MAGLINK LX4 CONSOLE, a valid user can change their privileges to administrator. | Sep 25, 2024 | 8.8 | 25 | NO | NO |
CVE-2023-38256HIGH Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3
vulnerable to a path traversal attack, which could allow | Sep 11, 2023 | 7.5 | 22 | NO | NO |
CVE-2024-41725MEDIUM ProGauge MAGLINK LX CONSOLE does not have sufficient filtering on input
fields that are used to render pages which may allow cross site
scripting. | Sep 25, 2024 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Doverfuelingsolutions.
Media articles that mention a CVE ID that affects a product developed by Doverfuelingsolutions — matched by CVE ID, not by vendor name.