CISA Flags Fuel-Boss Shared PHP Exposure

CISA warned that All-Line Equipment Company’s Fuel-Boss V1 Standard, Portal, Master/Slave, and Backflush Systems all share PHP_7.1.5 and are affected by CVE-2018-19518 and CVE-2019-11043. CISA says successful exploitation could let an attacker run arbitrary commands or code remotely on those systems. The two flaws hit the same runtime in different ways: one can turn an untrusted IMAP server name into command execution, and the other abuses PHP-FPM’s FastCGI handling to overflow memory and reach code execution. Because the vulnerable PHP build sits under multiple Fuel-Boss modes, the exposure is shared rather than isolated to one screen or module. Fixes exist for Fuel-Boss V1 Standard and Portal, but CISA says Master/Slave has no fix yet and Backflush has no planned fix. For deployments that cannot be patched, the remaining exposure stays with the system boundary itself, especially where the product is reachable from the Internet or broadly accessible on internal networks.

Part of the PlainSec briefing for 2026-08-27

Editions

CVEs

Sources