CISA Advisory: Critical Vulnerabilities in All-Line Equipment Company Fuel-Boss
CISA released an advisory detailing two critical vulnerabilities in All-Line Equipment Company Fuel-Boss, a fuel management system used in critical infrastructure sectors. The vulnerabilities, CVE-2018-19518 and CVE-2019-11043, affect Fuel-Boss V1 Standard, Portal, Master/Slave, and Backflush Systems running PHP 7.1.5. Successful exploitation could allow remote attackers to execute arbitrary commands or code. Fixes are available for Standard and Portal versions, but not yet for Master/Slave, and no fix is planned for Backflush Systems. CISA recommends taking affected products offline or restricting network access.
What we know
Affected products: Fuel-Boss V1 Standard, Portal, Master/Slave, and Backflush Systems, all running PHP 7.1.5.
▤ 1 sources›
CISA published an advisory on 2026-08-27 regarding vulnerabilities in All-Line Equipment Company Fuel-Boss.
▤ 1 sources›
CISA recommends taking affected products off the internet or restricting IP access.
▤ 1 sources›
Two CVEs are identified: CVE-2018-19518 (argument injection) and CVE-2019-11043 (buffer overflow).
▤ 1 sources›
Fixes are available for Standard and Portal versions.
▤ 1 sources›
No fix is planned for Backflush Systems.
▤ 1 sources›
Fixes are not yet available for Master/Slave.
▤ 1 sources›
Successful exploitation could allow remote code execution.
▤ 1 sources›
CISA published an advisory on critical vulnerabilities in All-Line Equipment Company Fuel-Boss, affecting multiple product versions. Exploitation could allow remote code execution. Fixes are available for some versions, but not all.
Verified · 1 sourcesLive reports
View allComments 0
Discuss this event in persistent threads. Live chat remains separate.
No comments yet. Start the conversation.