Frangoteam

Fuxa

34 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 11.39%
  • Veröffentlicht 09.02.2026 22:21:03
  • Zuletzt bearbeitet 13.02.2026 20:31:09

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authorization bypass vulnerability in the FUXA allows an unauthenticated, remote attacker to create and modify arbitrary schedulers, expo...

  • EPSS 0.98%
  • Veröffentlicht 09.02.2026 22:18:15
  • Zuletzt bearbeitet 13.02.2026 20:31:47

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to execute arbitrary code on the server when the Node-RED p...

  • EPSS 0.48%
  • Veröffentlicht 06.02.2026 19:16:10
  • Zuletzt bearbeitet 10.02.2026 14:31:52

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An authorization bypass vulnerability in FUXA allows an unauthenticated, remote attacker to modify device tags via WebSockets. Exploitation allows an unauthenticated, remote at...

  • EPSS 0.27%
  • Veröffentlicht 06.02.2026 19:16:10
  • Zuletzt bearbeitet 10.02.2026 14:33:38

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An information disclosure vulnerability in FUXA allows an unauthenticated, remote attacker to retrieve sensitive administrative database credentials. Exploitation allows an una...

  • EPSS 0.42%
  • Veröffentlicht 03.02.2026 00:00:00
  • Zuletzt bearbeitet 11.02.2026 18:16:05

FUXA v1.2.7 allows Remote Code Execution (RCE) via the project import functionality. The application does not properly sanitize or sandbox user-supplied scripts within imported project files. An attacker can upload a malicious project containing syst...

  • EPSS 0.73%
  • Veröffentlicht 03.02.2026 00:00:00
  • Zuletzt bearbeitet 11.02.2026 18:16:05

FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks authentication mechanisms, allowing unauthenticated remote attackers to upload arbitrary files. This can be exploited to overwrite cr...

  • EPSS 2.04%
  • Veröffentlicht 03.02.2026 00:00:00
  • Zuletzt bearbeitet 28.02.2026 04:16:17

FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-coded secret key to sign and verify JWT Tokens. This allows remote attackers to forge valid admin tokens and bypass authentication to ...

  • EPSS 0.46%
  • Veröffentlicht 03.02.2026 00:00:00
  • Zuletzt bearbeitet 10.02.2026 14:47:43

FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' flag is commented out by default, causing the application to initialize with authentication disabled. This allows unauthenticated ...

Exploit
  • EPSS 27.23%
  • Veröffentlicht 22.09.2023 00:15:11
  • Zuletzt bearbeitet 21.11.2024 08:02:12

FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin.

Exploit
  • EPSS 1.48%
  • Veröffentlicht 22.09.2023 00:15:11
  • Zuletzt bearbeitet 21.11.2024 08:02:12

FUXA <= 1.1.12 is vulnerable to Local via Inclusion via /api/download.