Back

CRITICAL

FUXA Unauthenticated Remote Arbitrary Device Tag Write

Published Feb 6, 2026

Description

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An authorization bypass vulnerability in FUXA allows an unauthenticated, remote attacker to modify device tags via WebSockets. Exploitation allows an unauthenticated, remote attacker to bypass role-based access controls and overwrite arbitrary device tags or disable communication drivers, exposing connected ICS/SCADA environments to follow-on actions. This may allow an attacker to manipulate physical processes and disconnected devices from the HMI. This affects FUXA through version 1.2.9. This issue has been patched in FUXA version 1.2.10.

Affected products

Remediation

No remediation recorded yet.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Feb 6, 2026
Updated Feb 9, 2026
Reserved Feb 5, 2026
CISA Vulnrichment
Updated Feb 9, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Feb 6, 2026
Updated Feb 9, 2026
Exploited since n/a
EUVD-2026-5620 GHSA-GGXW-G3CP-MGF8