A critical command injection vulnerability, tracked as CVE-2025-58428, has been identified in the Veeder-Root TLS4B Automatic Tank Gauge (ATG) System. The flaw resides in the system's SOAP-based web services interface, which allows remote attackers with valid credentials to execute arbitrary system-level commands on the underlying Linux operating system. Successful exploitation could grant attackers full shell access, enable remote command execution, and facilitate lateral movement within affected networks, posing a significant risk to organizations relying on these systems for fuel management and monitoring.
Security advisories highlight that all versions of the TLS4B system prior to 11.A are affected. In addition to the command injection issue, the system is also vulnerable to an integer overflow related to Unix time handling, which could cause system resets after the 2038 epoch rollover. The vulnerabilities are rated as critical, with CVSS scores of 9.9 (v3.1) and 9.4 (v4), and could result in denial of service, administrative lockout, or disruption of core functionalities if exploited. Organizations are urged to review vendor guidance and apply mitigations to protect against these threats.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
CISA issued advisory ICSA-25-296-03 covering the two vulnerabilities affecting Veeder-Root TLS4B Automatic Tank Gauge Systems used in the energy sector worldwide. CISA also recommended minimizing internet exposure, segmenting control system networks, and using secure remote access methods, and said it had no reports of public exploitation at publication time.
Veeder-Root recommended that customers upgrade affected TLS4B Automatic Tank Gauge Systems to version 11.A to remediate the command injection vulnerability. For the time-handling flaw, customers were advised to apply network security best practices pending a vendor fix.
Veeder-Root disclosed CVE-2025-55067, an integer overflow issue tied to Unix time handling in TLS4B systems that can reset the clock to 1901. The bug may cause authentication failures, administrative lockout, corrupted logs, and denial of service, and no fix was yet available at the time of publication.
Veeder-Root identified CVE-2025-58428, a command injection vulnerability in the SOAP-based web services interface of TLS4B Automatic Tank Gauge Systems before version 11.A. The flaw could allow a remote attacker with valid credentials to execute system-level commands, obtain full shell access, and potentially move laterally on the network.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.