FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This affects FUXA through version 1.2.9. This issue has been patched in FUXA version 1.2.10.
The vulnerability (CWE-22) results from improper validation of file paths submitted to the application, which allows an attacker to escape the allowed directory through traversal sequences (e.g., '../'). Additionally, the lack of required authentication (CWE-306) means the exploit can be performed without any credentials. An attacker can thus write malicious files anywhere on the file system of the server running FUXA.
An attacker can write arbitrary files to critical locations on the server's operating system, which in practice can lead to remote code execution (RCE), takeover of server control, or disruption of SCADA/HMI industrial systems. The impact includes confidentiality, integrity, and availability of the system and dependent systems.
The FUXA software must be immediately updated to version 1.2.10, in which the vulnerability has been fixed. The patch is available in the official GitHub project repository and in release v1.2.10.
FUXA (Frangoteam) in all versions up to and including 1.2.9.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XFrangoteam Fuxa
APPFrangoteam< 1.2.10
Related vulnerabilities
FUXA – pominięcie uwierzytelnienia przez nagłówek Referer prowadzące do RCE
FUXA SCADA/HMI: Auth Bypass + RCE przez API heartbeat
FUXA SCADA/HMI – pominięcie uwierzytelnienia umożliwiające RCE przez plugin Node-RED
FUXA SCADA: domyślny sekret JWT umożliwia nieautoryzowany dostęp i RCE
FUXA SCADA: authorization bypass umożliwia modyfikację schedulerów bez uwierzytelnienia