📦 Fuxa

by Frangoteam

🔍 What is Fuxa?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-69985

CRITICAL CVSS 9.8 Feb 24, 2026

CVE-2025-69985 is an authentication bypass vulnerability in FUXA SCADA/HMI software that allows remote unauthenticated attackers to execute arbitrary Node.js code on affected servers. The vulnerabilit...

CVE-2026-25938

CRITICAL CVSS 9.8 Feb 9, 2026

An authentication bypass vulnerability in FUXA web-based SCADA/HMI software allows unauthenticated remote attackers to execute arbitrary code on the server when the Node-RED plugin is enabled. This af...

CVE-2026-25939

CRITICAL CVSS 9.1 Feb 9, 2026

An authorization bypass vulnerability in FUXA web-based SCADA/HMI software allows unauthenticated remote attackers to create and modify arbitrary schedulers. This affects FUXA versions 1.2.8 through 1...

CVE-2026-25893

CRITICAL CVSS 9.8 Feb 9, 2026

An authentication bypass vulnerability in FUXA web-based SCADA/HMI software allows unauthenticated remote attackers to gain administrative access via the heartbeat refresh API. This can lead to arbitr...

CVE-2026-25894

CRITICAL CVSS 9.8 Feb 9, 2026

An insecure default configuration in FUXA web-based SCADA/HMI software allows unauthenticated remote attackers to gain administrative access and execute arbitrary code on the server. This affects FUXA...

CVE-2026-25895

CRITICAL CVSS 9.8 Feb 9, 2026

CVE-2026-25895 is a path traversal vulnerability in FUXA web-based SCADA/HMI software that allows unauthenticated remote attackers to write arbitrary files anywhere on the server filesystem. This affe...

CVE-2025-69971

CRITICAL CVSS 9.8 Feb 3, 2026

FUXA v1.2.7 contains a hard-coded JWT secret key that allows attackers to forge valid authentication tokens. This enables complete authentication bypass and administrative access to affected systems. ...

CVE-2025-69981

CRITICAL CVSS 9.8 Feb 3, 2026

FUXA v1.2.7 has an unauthenticated file upload vulnerability in the /api/upload endpoint that allows remote attackers to upload arbitrary files. This can lead to system compromise through database ove...

CVE-2025-69983

CRITICAL CVSS 9.8 Feb 3, 2026

CVE-2025-69983 is a critical remote code execution vulnerability in FUXA v1.2.7 that allows attackers to execute arbitrary system commands through malicious project imports. This affects all organizat...

CVE-2023-33831

CRITICAL CVSS 9.8 Sep 18, 2023

This is an unauthenticated remote command execution vulnerability in FUXA SCADA/HMI software that allows attackers to execute arbitrary commands on affected systems via a crafted POST request to the /...

CVE-2026-25951

HIGH CVSS 7.2 Feb 9, 2026

CVE-2026-25951 is a path traversal vulnerability in FUXA web-based SCADA/HMI software that allows authenticated administrators to bypass directory protections using nested traversal sequences. This en...