Frangoteam

Fuxa

34 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.37%
  • Veröffentlicht 10.08.2026 10:41:33
  • Zuletzt bearbeitet 10.08.2026 14:17:29

A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated remote attacker to query all historical sensor data via the DAQ_QUERY Socket.IO event. When secureEnabled=true, all other sensitive Socket.IO events (DE...

  • EPSS 0.67%
  • Veröffentlicht 21.07.2026 21:33:09
  • Zuletzt bearbeitet 23.07.2026 15:49:31

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an unauthenticated Remote Code Execution vulnerability when `secureEnabled` is set to `true`. The `POST /api/runscript` endpoint checks authorization against ...

  • EPSS 0.54%
  • Veröffentlicht 21.07.2026 21:27:29
  • Zuletzt bearbeitet 23.07.2026 15:49:31

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an authorization bypass in the /api/getTagValue endpoint allows unauthenticated access to tag values when the referenced script does not exist. Version 1.3.1 ...

  • EPSS 0.86%
  • Veröffentlicht 21.07.2026 21:24:59
  • Zuletzt bearbeitet 23.07.2026 15:49:31

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to achieve Full Remote Code Execution (RCE) as root. The exploit succeeds even when the platform is configu...

  • EPSS 0.35%
  • Veröffentlicht 30.06.2026 20:24:33
  • Zuletzt bearbeitet 01.07.2026 18:17:31

FUXA versions 1.3.1 and prior contain an authentication bypass vulnerability via dot-segment path normalization in the REST API. The API router fails to normalize dot-segment sequences before applying authentication middleware, allowing unauthenticat...

Exploit
  • EPSS 5.63%
  • Veröffentlicht 24.02.2026 00:00:00
  • Zuletzt bearbeitet 26.02.2026 19:39:20

FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trusts the HTTP "Referer" header to validate internal r...

Medienbericht
  • EPSS 10.35%
  • Veröffentlicht 09.02.2026 22:29:48
  • Zuletzt bearbeitet 13.02.2026 20:32:48

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This affects FUXA th...

  • EPSS 0.76%
  • Veröffentlicht 09.02.2026 22:28:46
  • Zuletzt bearbeitet 13.02.2026 20:33:42

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An insecure default configuration in FUXA allows an unauthenticated, remote attacker to gain administrative access and execute arbitrary code on the server. This affects FUXA t...

  • EPSS 0.68%
  • Veröffentlicht 09.02.2026 22:26:45
  • Zuletzt bearbeitet 13.02.2026 20:35:25

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to gain administrative access via the heartbeat refresh API and execu...

  • EPSS 1.22%
  • Veröffentlicht 09.02.2026 22:24:25
  • Zuletzt bearbeitet 13.02.2026 20:28:36

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.11, there is a flaw in the path sanitization logic allows an authenticated attacker with administrative privileges to bypass directory traversal protections. By us...