CVE-2026-72586
- EPSS 0.37%
- Veröffentlicht 10.08.2026 10:41:33
- Zuletzt bearbeitet 10.08.2026 14:17:29
A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated remote attacker to query all historical sensor data via the DAQ_QUERY Socket.IO event. When secureEnabled=true, all other sensitive Socket.IO events (DE...
CVE-2026-43947
- EPSS 0.67%
- Veröffentlicht 21.07.2026 21:33:09
- Zuletzt bearbeitet 23.07.2026 15:49:31
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an unauthenticated Remote Code Execution vulnerability when `secureEnabled` is set to `true`. The `POST /api/runscript` endpoint checks authorization against ...
CVE-2026-43946
- EPSS 0.54%
- Veröffentlicht 21.07.2026 21:27:29
- Zuletzt bearbeitet 23.07.2026 15:49:31
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an authorization bypass in the /api/getTagValue endpoint allows unauthenticated access to tag values when the referenced script does not exist. Version 1.3.1 ...
CVE-2026-43945
- EPSS 0.86%
- Veröffentlicht 21.07.2026 21:24:59
- Zuletzt bearbeitet 23.07.2026 15:49:31
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to achieve Full Remote Code Execution (RCE) as root. The exploit succeeds even when the platform is configu...
CVE-2026-13207
- EPSS 0.35%
- Veröffentlicht 30.06.2026 20:24:33
- Zuletzt bearbeitet 01.07.2026 18:17:31
FUXA versions 1.3.1 and prior contain an authentication bypass vulnerability via dot-segment path normalization in the REST API. The API router fails to normalize dot-segment sequences before applying authentication middleware, allowing unauthenticat...
CVE-2025-69985
- EPSS 5.63%
- Veröffentlicht 24.02.2026 00:00:00
- Zuletzt bearbeitet 26.02.2026 19:39:20
FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trusts the HTTP "Referer" header to validate internal r...
CVE-2026-25895
- EPSS 10.35%
- Veröffentlicht 09.02.2026 22:29:48
- Zuletzt bearbeitet 13.02.2026 20:32:48
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This affects FUXA th...
CVE-2026-25894
- EPSS 0.76%
- Veröffentlicht 09.02.2026 22:28:46
- Zuletzt bearbeitet 13.02.2026 20:33:42
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An insecure default configuration in FUXA allows an unauthenticated, remote attacker to gain administrative access and execute arbitrary code on the server. This affects FUXA t...
CVE-2026-25893
- EPSS 0.68%
- Veröffentlicht 09.02.2026 22:26:45
- Zuletzt bearbeitet 13.02.2026 20:35:25
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to gain administrative access via the heartbeat refresh API and execu...
CVE-2026-25951
- EPSS 1.22%
- Veröffentlicht 09.02.2026 22:24:25
- Zuletzt bearbeitet 13.02.2026 20:28:36
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.11, there is a flaw in the path sanitization logic allows an authenticated attacker with administrative privileges to bypass directory traversal protections. By us...