All-Line Equipment Company Fuel-Boss
2026-08-27T19:23:18Z•065a2019dcebd52d01434ecc2024aa72fa38006e05e0490fec86dc47d1c366f5
CVE-2018-1285CVE-2018-19518CVE-2019-11043CVE-2025-2399CVE-2025-3511CVE-2026-18717CVE-2026-69658CVE-2026-71187CVE-2026-73125CVE-2026-73809CVE-2026-73819CVE-2026-75112CVE-2026-75548CVE-2026-75814CVE-2026-76133CVE-2026-76179CVE-2026-76940CVE-2026-76943CVE-2026-77966CVE-2026-77975CVE-2026-77977CVE-2026-78037CVE-2026-78239All-Line Equipment CompanyApplied Systems EngineeringCISA ICS advisoryEbyteMitsubishi ElectricOT securityRockwell AutomationTLS certificate validationXXEXiiaozetarbitrary file readarbitrary file writeauthentication bypasscommand injectioncritical infrastructuredenial of serviceindustrial control systemsmissing authenticationremote code executionweak password hashing
What happened
CISA ICS advisories dated August 27, 2026 cover multiple vulnerable OT and industrial products. Highest-risk issues include unauthenticated or authenticated command injection and device takeover in Xiiaozet LK100W, broad compromise of Ebyte NA111-M, remote code execution in All-Line Fuel-Boss, and arbitrary file access, SSRF, and TLS certificate validation weaknesses in ASE2000. Additional advisories address weak password hashing in Rockwell OTTO Fleet Manager and denial-of-service vulnerabilities in Mitsubishi Electric FA and CNC products.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ics_advisories
- Record identifier
- 065a2019dcebd52d01434ecc2024aa72fa38006e05e0490fec86dc47d1c366f5
- Enrichment time
- 2026-08-27T19:23:18Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.