Back to overview

CVE-2025-58428

CRITICAL
9.9
CVSS 3.1
Description
The TLS4B ATG system's SOAP-based interface is vulnerable due to its accessibility through the web services handler. This vulnerability enables remote attackers with valid credentials to execute system-level commands on the underlying Linux system. This could allow the attacker to achieve remote command execution, full shell access, and potential lateral movement within the network.

Metadata

CVE ID
CVE-2025-58428
State
PUBLISHED
Assigner
icscert
Reserved
2025-09-23 19:56 UTC
Published
2025-10-23 19:49 UTC
Last updated
2025-10-23 20:29 UTC
Primary CWE
CWE-77
CWE-77 Improper Neutralization of Special Elements used in a…
Vendor / Product
Veeder-Root / TLS4B Automatic Tank Gauge System
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Veeder-Root TLS4B Automatic Tank Gauge System 0 < 11.A, 11.A
Weakness (CWE)
CWESourceDescription
CWE-77 cna CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
9.4 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Back to overview