CVE-2025-5310
Dover Fueling Solutions ProGauge MagLink LX Consoles expose an undocumented and unauthenticated target communication framework (TCF) interface on a specific port. Files can be created, deleted, or ...
Affects 0 products across 3 vendors.
Software does not perform any authentication for functionality that requires a verified identity.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
Dover Fueling Solutions ProGauge MagLink LX Consoles expose an undocumented and unauthenticated target communication framework (TCF) interface, which can be exploited to create, delete, or modify files, potentially leading to remote code execution.
BSID: BS-2025-GLOBAL-038431-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2025-5310?
What is the CVSS score for CVE-2025-5310?
Is CVE-2025-5310 actively exploited?
How do I remediate CVE-2025-5310?
What systems are affected by CVE-2025-5310?
| CVE ID | CVE-2025-5310 |
|---|---|
| BSID | BS-2025-GLOBAL-038431-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Published | 2025-06-27 |
| Last Modified | 2026-04-15 |
| ICS Relevance | 15% |
| Weakness (CWE) | |
| Source | NVD |
Dover Fueling Solutions ProGauge MagLink LX Consoles expose an undocumented and unauthenticated target communication framework (TCF) interface on a specific port. Files can be created, deleted, or modified, potentially leading to remote code execution.
Source: NIST NVD / MITRE CVE Database
The attack vector involves exploiting an undocumented and unauthenticated TCF interface on a specific port of the ProGauge MagLink LX Consoles. An attacker can send malicious commands to manipulate files, which could lead to remote code execution.
Exploitation Likelihood: CRITICAL
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 63f37ff2f931a1f790a34fda52c49a918ca396387e28c25ef9807e6c4ad9f15b6785c91473855107dc00ff6d4235f26f72c8a8756e0e1ae88df04cd897be0a8c |
Critical Severity - Know Your Exposure
A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →