Exposed Automated Tank Gauge Systems (DIVD-2025-00005) post, april 29, 2025mei 19, 2025 Automated Tank Gauge (ATG) systems are widely used in gas stations and other critical facilities to monitor fuel levels, detect leaks, and manage inventory. These industrial control systems have been found exposed directly to the internet without proper authentication mechanisms, creating significant security and potential safety risks. The vulnerability affects ATG systems from various manufacturers, most notably Veeder-Root models including TLS-250 and TLS-350. These devices, when connected directly to the internet, can be accessed by sending specific commands through their serial interfaces (typically on port 10001), potentially allowing attackers to view fuel levels, change tank labels and alarm thresholds, or even modify critical monitoring parameters. DIVD-2025-00005 – Exposed Automated Tank Gauge Systems | DIVD CSIRT: Exposed Automated Tank Gauge Systems (DIVD-2025-00005) vulnerability 2025