CVE-2025-58428 is a critical authenticated command injection vulnerability in the Veeder-Root TLS4B Automatic Tank Gauge (ATG) system. The flaw is in the SOAP-based web services interface exposed through the web services handler, where user-controlled SOAP input is passed to shell execution on the underlying Linux operating system without proper neutralization of shell metacharacters. Public reporting indicates that characters such as semicolons, pipes, and ampersands can be used to break out of the intended command context and inject arbitrary system commands. An attacker with valid credentials and network access to the SOAP interface can therefore execute system-level commands remotely on the device. The issue is remotely exploitable and has been associated with industrial control system deployments of TLS4B, including environments in the energy sector. Supporting content indicates affected TLS4B systems are versions prior to 11.A.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical command injection vulnerability in the Veeder-Root TLS4B Automatic Tank Gauge (ATG) system's SOAP-based interface that allows authenticated remote attackers to execute system-level commands on the underlying Linux system.
A critical authenticated command injection vulnerability in the SOAP-based web services interface of Veeder-Root TLS4B Automatic Tank Gauge systems that can allow arbitrary command execution and potentially full system compromise.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.