CRITICAL🇵🇱 Wersja polska

CVE-2026-25938

CVSS 9.5v4.0pub. 2026-02-09upd. 2026-02-13

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to execute arbitrary code on the server when the Node-RED plugin is enabled. This has been patched in FUXA version 1.2.11.

🤖 AI Analysis
How it works

The vulnerability results from errors of the CWE-290 class (authentication mechanism bypass via spoofing) and CWE-306 class (missing authentication for critical functionality). When the Node-RED plugin is enabled in FUXA, an attacker can bypass required authentication and gain access to functionality reserved for authenticated users. As a result, it is possible to upload and execute arbitrary code on the server without possessing any credentials.

Impact

An attacker without authentication can remotely execute arbitrary code on the server (RCE), which in a SCADA/HMI environment may lead to complete system takeover, disruption of industrial processes, or further lateral movement in the OT/IT network.

Mitigation & patch

FUXA should be updated to version 1.2.11, in which the vulnerability has been fixed. The patch is available in the official GitHub repository at the address indicated in the references (commit 5e7679b and release v1.2.11). Until the update is applied, it is recommended to disable the Node-RED plugin and restrict access to the FUXA interface to trusted networks only.

Who is affected

Frangoteam FUXA in versions 1.2.8 to 1.2.10 (inclusive) with the Node-RED plugin enabled.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Frangoteam Fuxa

    APP
    Frangoteam
    1.2.8 – 1.2.11 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEAuth Bypass
CWE
References

Related vulnerabilities

CVE-2025-69985CRITICAL9.8PL ✓same product

FUXA – pominięcie uwierzytelnienia przez nagłówek Referer prowadzące do RCE

CVE-2026-25893CRITICAL10.0PL ✓same product

FUXA SCADA/HMI: Auth Bypass + RCE przez API heartbeat

CVE-2026-25895CRITICAL9.5PL ✓same product

Path traversal w FUXA SCADA/HMI umożliwia zapis dowolnych plików

CVE-2026-25894CRITICAL9.5PL ✓same product

FUXA SCADA: domyślny sekret JWT umożliwia nieautoryzowany dostęp i RCE

CVE-2026-25939CRITICAL9.3PL ✓same product

FUXA SCADA: authorization bypass umożliwia modyfikację schedulerów bez uwierzytelnienia