Skip to content
  • NVDA
  • AAPL
  • MSFT
  • AMD
  • TSLA

CISA Warns of Fuel-Boss Vulnerabilities

CISA advisory highlights remote code execution risks in All-Line Fuel-Boss systems.

By TMRO Staff·1 min read

Key points

  • CISA advisory published Aug 27, 2026.
  • Affects Fuel-Boss V1 Standard, Portal, Master/Slave, Backflush.
  • Vulnerabilities allow remote code execution.
  • CVSS score 8.7.
  • Affected versions include PHP 7.1.5.

What happened

On August 27, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) released an advisory concerning vulnerabilities in All-Line Equipment Company's Fuel-Boss systems. The advisory identifies multiple affected product versions, including Fuel-Boss V1 Standard, V1 Portal, V1 Master/Slave, and V1 Backflush Systems, all running PHP version 7.1.5. The vulnerabilities are associated with CVE-2018-19518 and CVE-2019-11043, and carry a CVSS v3 score of 8.7.

Why it matters

Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems. This poses a significant risk to organizations using Fuel-Boss equipment, potentially leading to unauthorized access, data breaches, or disruption of operations. The advisory underscores the importance of applying patches or mitigations promptly.

Why it matters

Successful exploitation could allow attackers to execute arbitrary commands or code remotely, posing a significant risk to industrial systems.

Sources

TMRO Report writes original coverage based on the material listed above.