All-Line Equipment Company Fuel-Boss

2026-08-27T19:23:18Z065a2019dcebd52d01434ecc2024aa72fa38006e05e0490fec86dc47d1c366f5
CVE-2018-1285CVE-2018-19518CVE-2019-11043CVE-2025-2399CVE-2025-3511CVE-2026-18717CVE-2026-69658CVE-2026-71187CVE-2026-73125CVE-2026-73809CVE-2026-73819CVE-2026-75112CVE-2026-75548CVE-2026-75814CVE-2026-76133CVE-2026-76179CVE-2026-76940CVE-2026-76943CVE-2026-77966CVE-2026-77975CVE-2026-77977CVE-2026-78037CVE-2026-78239All-Line Equipment CompanyApplied Systems EngineeringCISA ICS advisoryEbyteMitsubishi ElectricOT securityRockwell AutomationTLS certificate validationXXEXiiaozetarbitrary file readarbitrary file writeauthentication bypasscommand injectioncritical infrastructuredenial of serviceindustrial control systemsmissing authenticationremote code executionweak password hashing

What happened

CISA ICS advisories dated August 27, 2026 cover multiple vulnerable OT and industrial products. Highest-risk issues include unauthenticated or authenticated command injection and device takeover in Xiiaozet LK100W, broad compromise of Ebyte NA111-M, remote code execution in All-Line Fuel-Boss, and arbitrary file access, SSRF, and TLS certificate validation weaknesses in ASE2000. Additional advisories address weak password hashing in Rockwell OTTO Fleet Manager and denial-of-service vulnerabilities in Mitsubishi Electric FA and CNC products.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ics_advisories
Record identifier
065a2019dcebd52d01434ecc2024aa72fa38006e05e0490fec86dc47d1c366f5
Enrichment time
2026-08-27T19:23:18Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · All-Line Equipment Company Fuel-Boss · Baitaphish