All-Line Equipment Company Fuel-Boss Argument Injection and Buffer Overflow Vulnerabilities
First seen Aug 29, 2026 · Updated Aug 29, 2026 · CVSS 8.7
All-Line Equipment Company's Fuel-Boss fuel management systems (Standard, Portal, Master/Slave, and Backflush variants) running PHP 7.1.5 or earlier are vulnerable to two high-severity flaws: an argument injection vulnerability in the PHP imap_open() function and a buffer overflow in PHP-FPM's FastCGI handling. Successful exploitation could allow remote attackers to execute arbitrary OS commands or code on affected systems, posing risk to critical manufacturing, defense, emergency services, and transportation sector operators using this equipment.
Technical Analysis
CVE-2018-19518 stems from the University of Washington IMAP Toolkit's imap_rimap and tcp_aopen functions, used by PHP's imap_open(), failing to sanitize IMAP server name arguments, enabling argument injection (e.g., via a crafted '-oProxyCommand' string) and a stack-based buffer overflow that can lead to remote code execution (CVSS 3.1: 7.5 High). CVE-2019-11043 is a buffer overflow in PHP-FPM under specific Nginx/FPM configurations, allowing writes past allocated buffers into FCGI protocol space, resulting in remote code execution (CVSS 3.1: 8.7 High, CVSS 4.0: 9.4 Critical). Both flaws affect legacy PHP 7.1.5 runtime embedded in Fuel-Boss V1 product lines; exploitation complexity is high but impact on confidentiality, integrity, and availability is severe. These are OT/ICS-focused vulnerabilities in fuel dispensing and backflush control systems with no known direct AI agent integration, so agent-system impact is not applicable here.
Affected Systems
All-Line Equipment Company Fuel-Boss V1 Standard, V1 Portal, V1 Master/Slave, and V1 Backflush Systems running PHP version 7.1.5 or earlier (PHP_7.1.5_7.1.5 range).
Indicators of Compromise
- No specific IOCs (hashes, IPs, domains) provided; this is a vulnerability disclosure, not an active exploitation campaign report.
Remediation Steps
- 1
Apply vendor fixes
Contact All-Line Equipment Company (866-356-3336) to obtain available fixes for Fuel-Boss V1 Standard and V1 Portal products.
- 2
Monitor for Master/Slave fix availability
No fix is currently available for Fuel-Boss V1 Master/Slave; monitor vendor communications for future patches.
- 3
Plan for Backflush Systems end-of-life
No fix is planned for Fuel-Boss V1 Backflush Systems; consider replacement or additional compensating controls.
- 4
Restrict network exposure
Remove unpatched devices from direct internet access and restrict access via router-level IP allowlisting.
- 5
Network segmentation
Place control system networks and devices behind firewalls and isolate them from business/IT networks.
- 6
Secure remote access
Use VPNs with up-to-date patching for any required remote access, recognizing VPN security depends on connected endpoint security.
- 7
Report suspicious activity
Follow internal incident response procedures and report suspected malicious activity to CISA for tracking and correlation.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.