CVE-2025-54807: Dover Fueling Solutions ProGauge MagLink LX 4 Devices Use of Hard-coded Cryptographic Key
The secret used for validating authentication tokens is hardcoded in device firmware for affected versions. An attacker who obtains the signing key can bypass authentication, gaining complete access to the system.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54807?
CVE-2025-54807 has a high severity rating due to the risk of authentication bypass.
How do I fix CVE-2025-54807?
To fix CVE-2025-54807, upgrade the affected ProGauge MagLink LX and LX Plus devices to version 4.20.3 or the LX Ultimate to version 5.20.3.
What causes CVE-2025-54807?
CVE-2025-54807 is caused by a hardcoded secret used for validating authentication tokens in the device firmware.
What can an attacker do with CVE-2025-54807?
An attacker who obtains the hardcoded signing key can bypass authentication and gain complete access to the affected system.
Which products are affected by CVE-2025-54807?
The affected products include Dover Fueling Solutions ProGauge MagLink LX4, LX Plus, and LX Ultimate devices prior to their respective fixed versions.