CVE-2024-43423
The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that cannot be changed.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.68%
- CWE
- CWE-259
- Published
- 2024-09-24
- Last modified
- 2026-03-13
Affected products
- Dover Fueling Solutions (DFS) ProGauge MAGLINK LX CONSOLE
- Dover Fueling Solutions (DFS) ProGauge MAGLINK LX4 CONSOLE
Weakness type
Related vulnerabilities
- CVE-2026-86673 — ningzichun Student Management System Database Connection database.php mysqli_connect hard-coded credentials
- CVE-2026-86276 — SourceCodester Syllabus-Aligned Learning Management & Examination System db.php hard-coded credentials
- CVE-2026-86150 — Tenda CP3 hostapd hard-coded credentials
- CVE-2026-70403 — XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the...
- CVE-2026-82808 — Inbox Foundry ActiveInbox Extension Google OAuth Client Secret service-worker.production-esm.js hard-coded credentials
- CVE-2026-78062 — vas3k TaxHacker JWT Secret config.ts envSchema.parse hard-coded credentials
- CVE-2026-23933 — Hardcoded session key in Zabbix 7.4
- CVE-2026-19901 — LB-LINK X-PRO easycwmp hard-coded credentials