External risk intelligence

TLS4B ATG System Command Execution Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2025-58428

The vulnerability resides in a SOAP-based web services interface of an ATG (Automatic Tank Gauge) system. Such management and monitoring interfaces in industrial or infrastructure hardware are commonly exposed to networks for remote access and operational visibility, making them reachable in typical deployment patterns.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability within the TLS4B ATG system's web services interface. The issue allows remote attackers with valid credentials to execute system-level commands, potentially leading to unauthorized remote command execution and broader network access. The main concern is confirming relevance and exposure to our operational technology environments.

  • Attackers can run system commands remotely.
  • Matters if operational technology interfaces are exposed.
  • Assess impact on critical infrastructure systems.

Attack Path

How an attacker could exploit the issue

An attacker with valid credentials could target the TLS4B ATG system's web services interface. This interface, accessible via the web, allows for remote interaction with the system, potentially leading to the execution of commands on the underlying Linux operating system.

  • Accessible via network.
  • Triggers via authenticated web service.
  • Leads to system command execution.

Live Threat

Current exploitation, exposure, and threat context

The TLS4B ATG system's SOAP interface could allow remote attackers with valid credentials to execute commands on the underlying Linux system. This could lead to remote command execution and potential lateral movement within the network when the system is accessible via its web services handler.

  • System-level commands on Linux.
  • Remote access via web services handler.
  • Unauthorized command execution and network access.

Operational Fix

Recommended remediation, mitigation, and detection steps

Ownership for this critical TLS4B ATG system vulnerability likely falls to infrastructure, platform, or operations teams responsible for the underlying Linux systems and the web services handler. Vendor management should also be engaged due to the specific system. The immediate first step is to identify all instances of the TLS4B ATG system, confirm its exposure and business criticality, and then assign an accountable owner for remediation planning.

  • Identify affected systems and owners.
  • Verify system reachability and criticality.
  • Plan remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the TLS4B ATG system?

The TLS4B is an Automatic Tank Gauge (ATG) system. It is specialized hardware used in industrial settings to monitor fuel levels and inventory in storage tanks. These systems act as critical infrastructure components, providing site operators with essential data for inventory management and environmental safety compliance.

What does CVE-2025-58428 mean for system security?

This vulnerability is classified as CWE-77, which refers to improper neutralization of special elements used in a command. In this specific case, it means the system's web interface fails to properly filter inputs, allowing someone to inject and run unauthorized commands directly on the underlying Linux operating system.

How can an attacker trigger this vulnerability?

The attack requires valid user credentials to access the system's SOAP-based web services handler. It is not triggered by unauthenticated web traffic or anonymous probes. If the attacker cannot authenticate to the management interface, they cannot initiate the sequence that leads to command execution.

Is my environment at risk according to Halo Surface Signal?

Halo Surface Signal indicates the risk is 'Likely' because these management interfaces are often intentionally placed on networks to enable remote monitoring and operational visibility. If your TLS4B device is reachable over a network rather than isolated on a local segment, it faces a higher probability of being targeted.

What should I do if I run TLS4B systems?

Begin by inventorying all TLS4B devices to confirm their network reachability and business role. Once identified, restrict access to the web services interface to only necessary, authorized users and monitor for unusual activity. Coordinate with your vendor to track available updates or specific security guidance for these systems.

References