All-Line Equipment Company Fuel-Boss
Act NowCVSS 8.7ICS-CERT ICSA-26-239-02Aug 27, 2026
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary
All-Line Equipment Company Fuel-Boss V1 systems contain improper input validation vulnerabilities (CWE-88, CWE-120) that allow remote attackers to execute arbitrary commands or code on affected systems without authentication. Affected products include Fuel-Boss V1 Standard, V1 Portal, V1 Master/Slave, and V1 Backflush Systems running PHP 7.1.5. Vendor fixes are available for V1 Standard and V1 Portal only. No fix is planned for V1 Backflush Systems, and V1 Master/Slave fixes are not yet available.
What this means
What could happen
An attacker could execute arbitrary commands on your Fuel-Boss system, potentially allowing them to modify fuel dispensing parameters, alter transaction records, or disrupt refueling operations at your facility.
Who's at risk
This affects fuel management and dispensing facilities using All-Line Equipment Company Fuel-Boss systems. Any site with V1 Standard, V1 Portal, V1 Master/Slave, or V1 Backflush Systems deployed should evaluate their exposure, especially if these systems manage fuel inventory, billing, or pump control at gas stations, municipal fuel depots, or industrial refueling operations.
How it could be exploited
An attacker on the network sends a specially crafted request to the Fuel-Boss web interface (port 80/443). Due to improper input validation (CWE-88, CWE-120), the application executes the attacker's code directly on the server. No credentials or user interaction are required.
Prerequisites
- Network access to the Fuel-Boss web interface (HTTP/HTTPS port)
- Fuel-Boss system running vulnerable PHP 7.1.5 version
- No firewall rule restricting access to the Fuel-Boss management interface
remotely exploitableno authentication requiredactively exploited (KEV)extremely high EPSS score (99.8%)no patch available for some productsaffects critical operational systems
Exploitability
Actively exploited — confirmed by CISA KEV
Metasploit module available — weaponized exploitView module ↗
Public Proof-of-Concept (PoC) on GitHub (10 repositories)
Affected products (4)
4 with fix
ProductAffected VersionsFix Status
Fuel-Boss V1 Standard: >=|<=PHP_7.1.5_7.1.5≥ |≤ PHP 7.1.5 7.1.5Fix available
Fuel-Boss V1 Portal: >=|<=PHP_7.1.5_7.1.5≥ |≤ PHP 7.1.5 7.1.5Fix available
Fuel-Boss V1 Master/Slave: >=|<=PHP_7.1.5_7.1.5≥ |≤ PHP 7.1.5 7.1.5Fix available
Fuel-Boss V1 Backflush Systems: >=|<=PHP_7.1.5_7.1.5≥ |≤ PHP 7.1.5 7.1.5Fix available
Remediation & Mitigation
0/4
Do now
0/4HOTFIXContact All-Line Equipment Company (866-356-3336) and apply the vendor-supplied patch to Fuel-Boss V1 Standard and V1 Portal systems immediately
WORKAROUNDFor Fuel-Boss V1 Master/Slave systems (no patch available), disconnect from the Internet or restrict access to the management interface using firewall rules to allow only known trusted IP addresses and personnel workstations
HARDENINGFor Fuel-Boss V1 Backflush Systems (no fix planned), take the system offline or isolate it on an air-gapped network segment with no Internet or untrusted network access
HARDENINGIf Fuel-Boss systems must remain on the network, implement network segmentation with firewall rules to restrict HTTP/HTTPS access only from authorized management workstations and block all other inbound traffic
CVEs (2)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/ff8a77f0-de6b-45f8-859e-cfa1e0e5e04fGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.