Vendorsfrangoteamfuxaall versions
Vulnerabilities

frangoteam FUXA

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19CVEs
CVE-2026-25893
FUXA Unauthenticated Remote Code Execution via Admin JWT Minting
Published 2026-02-09 · Analyzed
10.0EPSS 0.011
CVE-2023-31719
FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin.
Published 2023-09-21 · Modified
9.8EPSS 0.260
CVE-2023-33831
A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request.
Published 2023-09-18 · Modified
9.8EPSS 0.260
CVE-2026-25895
FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API
Published 2026-02-09 · Analyzed
9.81 PoCEPSS 0.062
CVE-2025-69985
FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trusts the HTTP "Referer" header to validate internal requests. A remote unauthenticated attacker can bypass JWT authentication by spoofing the Referer header to match the server's host. Successful exploitation allows the attacker to access the protected /api/runscript endpoint and execute arbitrary Node.js code on the server.
Published 2026-02-24 · Analyzed
9.81 PoCEPSS 0.057
CVE-2025-69971
FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-coded secret key to sign and verify JWT Tokens. This allows remote attackers to forge valid admin tokens and bypass authentication to gain full administrative access.
Published 2026-02-03 · Modified
9.8EPSS 0.021
CVE-2026-25938
FUXA Unauthenticated Remote Code Execution in Node-RED Integration
Published 2026-02-09 · Analyzed
9.8EPSS 0.013
CVE-2026-25894
FUXA Unauthenticated Remote Code Execution via Hardcoded JWT Secret in Default Configuration
Published 2026-02-09 · Analyzed
9.8EPSS 0.012
CVE-2025-69981
FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks authentication mechanisms, allowing unauthenticated remote attackers to upload arbitrary files. This can be exploited to overwrite critical system files (such as the SQLite user database) to gain administrative access, or to upload malicious scripts to execute arbitrary code.
Published 2026-02-03 · Modified
9.8EPSS 0.008
CVE-2025-69983
FUXA v1.2.7 allows Remote Code Execution (RCE) via the project import functionality. The application does not properly sanitize or sandbox user-supplied scripts within imported project files. An attacker can upload a malicious project containing system commands, leading to full system compromise.
Published 2026-02-03 · Modified
9.8EPSS 0.004
CVE-2026-25939
FUXA Unauthenticated Remote Arbitrary Scheduler Write
Published 2026-02-09 · Analyzed
9.3EPSS 0.008
CVE-2026-25752
FUXA Unauthenticated Remote Arbitrary Device Tag Write
Published 2026-02-06 · Analyzed
9.3EPSS 0.007
CVE-2025-69970
FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' flag is commented out by default, causing the application to initialize with authentication disabled. This allows unauthenticated remote attackers to access sensitive API endpoints, modify projects, and control industrial equipment immediately after installation.
Published 2026-02-03 · Analyzed
9.3EPSS 0.005
CVE-2026-25751
FUXA Unauthenticated Exposure of Plaintext Database Credentials
Published 2026-02-06 · Analyzed
9.1EPSS 0.004
CVE-2026-25951
FUXA has a Path Traversal Sanitization Bypass
Published 2026-02-09 · Analyzed
8.6EPSS 0.017
CVE-2023-31717
A SQL Injection attack in FUXA <= 1.1.12 allows exfiltration of confidential information from the database.
Published 2023-09-21 · Modified
7.5EPSS 0.018
CVE-2023-31718
FUXA <= 1.1.12 is vulnerable to Local via Inclusion via /api/download.
Published 2023-09-21 · Modified
7.5EPSS 0.017
CVE-2021-45851
A Server-Side Request Forgery (SSRF) attack in FUXA 1.1.3 can be carried out leading to the obtaining of sensitive information from the server's internal environment and services, often potentially leading to the attacker executing commands on the server.
Published 2022-03-16 · Modified
7.5EPSS 0.015
CVE-2023-31716
FUXA <= 1.1.12 has a Local File Inclusion vulnerability via file=fuxa.log
Published 2023-09-21 · Modified
7.5EPSS 0.014