CVE-2025-58428
Command Injection in Veeder-Root TLS4B Automatic Tank Gauge System
Vexday Risk Score
28Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 9.4EPSS 1.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
23 out 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
The TLS4B ATG system's SOAP-based interface is vulnerable due to its accessibility through the web services handler. This vulnerability enables remote attackers with valid credentials to execute system-level commands on the underlying Linux system. This could allow the attacker to achieve remote command execution, full shell access, and potential lateral movement within the network.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Produtos afetados
Veeder-Root · TLS4B Automatic Tank Gauge SystemQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →