CRITICAL🇵🇱 Wersja polska

CVE-2026-25895

CVSS 9.5v4.0pub. 2026-02-09upd. 2026-02-13

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This affects FUXA through version 1.2.9. This issue has been patched in FUXA version 1.2.10.

🤖 AI Analysis
How it works

The vulnerability (CWE-22) results from improper validation of file paths submitted to the application, which allows an attacker to escape the allowed directory through traversal sequences (e.g., '../'). Additionally, the lack of required authentication (CWE-306) means the exploit can be performed without any credentials. An attacker can thus write malicious files anywhere on the file system of the server running FUXA.

Impact

An attacker can write arbitrary files to critical locations on the server's operating system, which in practice can lead to remote code execution (RCE), takeover of server control, or disruption of SCADA/HMI industrial systems. The impact includes confidentiality, integrity, and availability of the system and dependent systems.

Mitigation & patch

The FUXA software must be immediately updated to version 1.2.10, in which the vulnerability has been fixed. The patch is available in the official GitHub project repository and in release v1.2.10.

Who is affected

FUXA (Frangoteam) in all versions up to and including 1.2.9.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Frangoteam Fuxa

    APP
    Frangoteam
    < 1.2.10
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2025-69985CRITICAL9.8PL ✓same product

FUXA – pominięcie uwierzytelnienia przez nagłówek Referer prowadzące do RCE

CVE-2026-25893CRITICAL10.0PL ✓same product

FUXA SCADA/HMI: Auth Bypass + RCE przez API heartbeat

CVE-2026-25938CRITICAL9.5PL ✓same product

FUXA SCADA/HMI – pominięcie uwierzytelnienia umożliwiające RCE przez plugin Node-RED

CVE-2026-25894CRITICAL9.5PL ✓same product

FUXA SCADA: domyślny sekret JWT umożliwia nieautoryzowany dostęp i RCE

CVE-2026-25939CRITICAL9.3PL ✓same product

FUXA SCADA: authorization bypass umożliwia modyfikację schedulerów bez uwierzytelnienia