- EPSS 0.31%
- Veröffentlicht 18.08.2026 20:08:23
- Zuletzt bearbeitet 19.08.2026 16:18:49
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.3, DELETE /api/roles removes role definitions through server/runtime/users/usrstorage.js but does not remove the deleted role identifier from each user's info.role...
CVE-2026-65984
- EPSS 0.47%
- Veröffentlicht 18.08.2026 20:07:24
- Zuletzt bearbeitet 19.08.2026 19:17:22
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, POST /api/refresh in server/api/auth/index.js falls back from current user data to decoded.groups, including when the user is deleted or groups is zero, a...
CVE-2026-67443
- EPSS 0.62%
- Veröffentlicht 18.08.2026 20:06:15
- Zuletzt bearbeitet 18.08.2026 20:17:22
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the allowDashboard authorization gate in server/integrations/node-red/index.js calls authJwt.verify for /nodered without inspecting the decoded identity. ...
- EPSS 0.34%
- Veröffentlicht 18.08.2026 20:05:15
- Zuletzt bearbeitet 19.08.2026 19:17:22
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the device-webapi-request Socket.IO handler in server/runtime/index.js permits an authenticated non-admin runtime user to control property.address, causin...
CVE-2026-67440
- EPSS 0.49%
- Veröffentlicht 18.08.2026 20:03:38
- Zuletzt bearbeitet 19.08.2026 13:17:51
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the DEVICE_BROWSE, DEVICE_NODE_ATTRIBUTE, HOST_INTERFACES, and DEVICE_TAGS_REQUEST handlers in server/runtime/index.js return device-discovery, node-attri...
CVE-2026-47721
- EPSS 0.32%
- Veröffentlicht 18.08.2026 20:00:19
- Zuletzt bearbeitet 19.08.2026 16:17:12
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/scheduler and DELETE /api/scheduler in server/api/scheduler/index.js do not consistently enforce authJwt.haveAdminPermission for scheduler settings. A...
CVE-2026-47719
- EPSS 0.48%
- Veröffentlicht 18.08.2026 19:59:28
- Zuletzt bearbeitet 18.08.2026 20:17:15
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY Socket.IO handlers in server/runtime/index.js omit isSocketWriteAuthorized and accept attacker-controlled property...
CVE-2026-47720
- EPSS 0.49%
- Veröffentlicht 18.08.2026 19:58:26
- Zuletzt bearbeitet 19.08.2026 13:17:45
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengine DAQ storage connector's escapeTdString function in server/runtime/storage/tdengine/index.js doubles single quotes but does not escape backslashes. ...
CVE-2026-47718
- EPSS 0.27%
- Veröffentlicht 12.08.2026 22:21:26
- Zuletzt bearbeitet 14.08.2026 23:16:32
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid-token requests to read project, alarms, and scheduler APIs. Version 1.3.1 fixes this issue.
CVE-2026-47717
- EPSS 1.2%
- Veröffentlicht 12.08.2026 22:18:04
- Zuletzt bearbeitet 13.08.2026 13:19:08
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. Version 1...