Franklin Fueling Systems' vulnerability profile concentrates in a specialized line of fuel-management and point-of-sale hardware and firmware—particularly the TS-550 EVO platform and Colibri firmware—that operate in retail fuel-distribution environments. Vulnerabilities affecting the vendor skew toward critical severity and frequently acquire public exploit code; the recurring weakness classes, including path traversal, missing or incorrect authorization, and insufficient password-hashing practices, reflect the embedded nature and legacy authentication design of fuel-dispensing and transaction systems. Defenders operating fuel-management networks should prioritize patching for these products, as the combination of critical-severity outcomes and public exploit availability creates operational risk; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Franklinfueling over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-46417HIGH Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privileges in Franklin Fueling Systems Colibri Controller Module 1.8. | Apr 7, 2022 | 7.5 | 76 | NO | YES |
CVE-2013-7248HIGH Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 has a hardcoded password for the roleDiag account, which allows remote attackers to gai | Jan 26, 2014 | 10.0 | 41 | NO | YES |
CVE-2022-44039CRITICAL Franklin Fueling System FFS Colibri 1.9.22.8925 is affected by: File system overwrite. The impact is: File system rewrite (remote). ¶¶ An attacker can overwrite system files like [ | Dec 5, 2022 | 9.8 | 29 | NO | NO |
CVE-2023-5846CRITICAL
Franklin Fueling System TS-550 versions prior to 1.9.23.8960 are vulnerable to attackers decoding admin credentials, resulting in unauthenticated access to the device.
| Nov 2, 2023 | 9.8 | 27 | NO | NO |
CVE-2021-46421HIGH Franklin Fueling Systems FFS T5 Series 1.8.7.7299 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to obtain sensitive information. | Apr 27, 2022 | 7.5 | 26 | NO | NO |
CVE-2021-46420HIGH Franklin Fueling Systems FFS TS-550 evo 2.23.4.8936 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to obtain sensitive information. | Apr 27, 2022 | 7.5 | 26 | NO | NO |
CVE-2013-7247MEDIUM cgi-bin/tsaws.cgi in Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 allows remote attackers to discover sensitive information (user na | Jan 26, 2014 | 5.0 | 24 | NO | YES |
CVE-2017-6565HIGH On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the roleDiag user, which can be obtained by exploiting CVE-2013-7247, has the ability to upload files to the server hosti | May 1, 2017 | 8.8 | 22 | NO | NO |
CVE-2017-6564MEDIUM On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the Guest user, which contains the lowest privileges, can post to the idSourceFileName parameter found within the /downlo | May 1, 2017 | 6.5 | 22 | NO | NO |
CVE-2023-5885MEDIUM The discontinued FFS Colibri product allows a remote user to access files on the system including files containing login credentials for other users.
| Nov 27, 2023 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Franklinfueling.
Media articles that mention a CVE ID that affects a product developed by Franklinfueling — matched by CVE ID, not by vendor name.