FUXA Unauthenticated Remote Arbitrary Device Tag Write
Published Feb 6, 2026
9.3
CRITICALCVSS 4.0
EPSS 0.74%
Description
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An authorization bypass vulnerability in FUXA allows an unauthenticated, remote attacker to modify device tags via WebSockets. Exploitation allows an unauthenticated, remote attacker to bypass role-based access controls and overwrite arbitrary device tags or disable communication drivers, exposing connected ICS/SCADA environments to follow-on actions. This may allow an attacker to manipulate physical processes and disconnected devices from the HMI. This affects FUXA through version 1.2.9. This issue has been patched in FUXA version 1.2.10.
Affected products
-
- Version < 1.2.10StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Frangoteam | FUXA | n/a |
|
- < 1.2.10
No data.
No Red Hat product state for this CVE.
fuxa-server
npm
Introduced 0 Fixed 1.2.10
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | fuxa-server | 0 | 1.2.10 |
Remediation
No remediation recorded yet.
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-5620 Advisory
- https://github.com/advisories/GHSA-ggxw-g3cp-mgf8 Advisory
- https://github.com/frangoteam/FUXA/commit/eb2d8a20964ce7acaa0f442a181390a5f726a1ae
- https://github.com/frangoteam/FUXA/releases/tag/v1.2.10 x_refsource_MISCRelease Notes
- https://github.com/frangoteam/FUXA/security/advisories/GHSA-ggxw-g3cp-mgf8 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-25752
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-5620 | Advisory | |
| https://github.com/advisories/GHSA-ggxw-g3cp-mgf8 | Advisory | |
| https://github.com/frangoteam/FUXA/commit/eb2d8a20964ce7acaa0f442a181390a5f726a1ae | ||
| https://github.com/frangoteam/FUXA/releases/tag/v1.2.10 | x_refsource_MISCRelease Notes | |
| https://github.com/frangoteam/FUXA/security/advisories/GHSA-ggxw-g3cp-mgf8 | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-25752 |
Change history (0)
No recorded changes yet.