900+ Fuel Tank Gauges Still Hanging Off the Public Internet
ATG systems in gas stations, hospitals, and military sites are exposed to known CVEs — and nobody owns the patch cycle.

More than 900 automatic tank gauge systems sitting on US infrastructure are reachable from the open internet, unauthenticated, and carrying CVEs that researchers have been screaming about for over a year.
These are the boxes that monitor underground fuel tanks at gas stations. They also show up in hospitals, airports, military bases, and any site that stores fuel or chemicals at scale. Vendors include Veeder-Root, Franklin Fueling, OPW, Alisonic, and others. The protocol stack is old. The deployment pattern is older.
The failure mode here is depressingly familiar. Operators put a serial-to-Ethernet bridge in front of equipment that was never meant to face a network, NAT a port through the site router so the fuel vendor can pull readings, and then forget the box exists for a decade.
The vulnerability set is not new. Bitsight researchers flagged a cluster of issues across multiple ATG vendors in 2024 covering authentication bypass, hardcoded credentials, OS command injection, and arbitrary file access. Several have CVEs assigned, including CVE-2024-45066 and CVE-2024-43693. CISA pushed ICS advisories. Patches exist for some. Deployment is a different story.
In practice, an attacker who can talk to one of these gauges can do more than read fuel levels. They can shut down the pumps. They can disable leak detection. They can manipulate the relay outputs that control physical equipment around the tank. Pro-Russia hacktivist crews have already taken credit for messing with ATGs in Europe and the US over the past two years, mostly as nuisance attacks, but the capability ceiling is much higher than nuisance.
Why are they still online? Two reasons. The site owner — a franchisee, a facilities manager, a base contractor — has no idea the device is internet-facing because the integrator set it up that way. And the integrator has no patch SLA because the contract was for installation, not lifecycle.
This is the same operational gap that keeps building automation systems and unauthenticated Modbus endpoints on Shodan year after year. ICS asset owners are not running CMDBs. Their MSPs are not running vulnerability scanners against the OT segment. Insurance underwriters do not ask.
One thing the post-mortem will say, when somebody finally pops a tank farm and not just a 7-Eleven: the CVEs were public, the advisories were public, the Shodan dorks were public.
If you operate fuel infrastructure, the operational takeaway is simple — get your ATGs off the public internet today, put them behind a VPN or a cellular APN, and rotate the default creds before you go home.



