Frangoteam Fuxa vulnerabilities
33 known vulnerabilities affecting frangoteam/fuxa.
Total CVEs
33
CISA KEV
0
Public exploits
6
Exploited in wild
4
Severity breakdown
CRITICAL14HIGH13MEDIUM5LOW1
Vulnerabilities
Page 2 of 2
CVE-2026-72586P3HIGHCVSS 7.5≤ 1.3.32026-08-10
CVE-2026-72586 [HIGH] CWE-306 CVE-2026-72586: A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated re
A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated remote attacker to query all historical sensor data via the DAQ_QUERY Socket.IO event. When secureEnabled=true, all other sensitive Socket.IO events (DEVICE_BROWSE, HOST_INTERFACES, DEVICE_TAGS_REQUEST, etc.) call isSocketAdminAuthorized to verify the con
nvd
CVE-2026-65984P3HIGHCVSS 7.5fixed in 1.3.32026-08-18
CVE-2026-65984 [HIGH] CWE-613 CVE-2026-65984: FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, POST
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, POST /api/refresh in server/api/auth/index.js falls back from current user data to decoded.groups, including when the user is deleted or groups is zero, and POST /api/heartbeat in server/api/index.js re-signs inbound JWT claims without validating the curren
nvd
CVE-2023-31717P3HIGHCVSS 7.5≤ 1.1.122023-09-22
CVE-2023-31717 [HIGH] CWE-89 CVE-2023-31717: A SQL Injection attack in FUXA <= 1.1.12 allows exfiltration of confidential information from the da
A SQL Injection attack in FUXA <= 1.1.12 allows exfiltration of confidential information from the database.
nvd
CVE-2026-25751P3HIGHCVSS 7.5fixed in 1.2.102026-02-06
CVE-2026-25751 [HIGH] CWE-306 CVE-2026-25751: FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An information disclosure
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An information disclosure vulnerability in FUXA allows an unauthenticated, remote attacker to retrieve sensitive administrative database credentials. Exploitation allows an unauthenticated, remote attacker to obtain the full system configuration, including administrative credenti
nvd
CVE-2023-31718P3HIGHCVSS 7.5≤ 1.1.122023-09-22
CVE-2023-31718 [HIGH] CWE-98 CVE-2023-31718: FUXA <= 1.1.12 is vulnerable to Local via Inclusion via /api/download.
FUXA <= 1.1.12 is vulnerable to Local via Inclusion via /api/download.
nvd
CVE-2026-67440P3MEDIUMCVSS 6.9fixed in 1.3.32026-08-18
CVE-2026-67440 [MEDIUM] CWE-862 CVE-2026-67440: FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the DEVICE_BROWSE, DEVICE_NODE_ATTRIBUTE, HOST_INTERFACES, and DEVICE_TAGS_REQUEST handlers in server/runtime/index.js return device-discovery, node-attribute, host-network-interface, and device-tag metadata without isSocketAdminAuthorized when secureEnabl
nvd
CVE-2026-47721P3MEDIUMCVSS 6.3fixed in 1.3.22026-08-18
CVE-2026-47721 [MEDIUM] CWE-862 CVE-2026-47721: FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/scheduler and DELETE /api/scheduler in server/api/scheduler/index.js do not consistently enforce authJwt.haveAdminPermission for scheduler settings. An authenticated non-admin operator can create or alter deviceActions that invoke onSetValue or onRunS
nvd
CVE-2021-45851P3HIGHCVSS 7.5v1.1.32022-03-16
CVE-2021-45851 [HIGH] CWE-918 CVE-2021-45851: A Server-Side Request Forgery (SSRF) attack in FUXA 1.1.3 can be carried out leading to the obtainin
A Server-Side Request Forgery (SSRF) attack in FUXA 1.1.3 can be carried out leading to the obtaining of sensitive information from the server's internal environment and services, often potentially leading to the attacker executing commands on the server.
ghsanvdosv
CVE-2023-31716P3HIGHCVSS 7.5≤ 1.1.122023-09-22
CVE-2023-31716 [HIGH] CWE-98 CVE-2023-31716: FUXA <= 1.1.12 has a Local File Inclusion vulnerability via file=fuxa.log
FUXA <= 1.1.12 has a Local File Inclusion vulnerability via file=fuxa.log
ghsanvdosv
CVE-2026-65985P3MEDIUMCVSS 6.0fixed in 1.3.32026-08-18
CVE-2026-65985 [MEDIUM] CWE-918 CVE-2026-65985: FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the device-webapi-request Socket.IO handler in server/runtime/index.js permits an authenticated non-admin runtime user to control property.address, causing the FUXA server to issue an outbound HTTP or HTTPS request and return the response body to the reque
nvd
CVE-2026-47720P3MEDIUMCVSS 5.3fixed in 1.3.22026-08-18
CVE-2026-47720 [MEDIUM] CWE-89 CVE-2026-47720: FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengi
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengine DAQ storage connector's escapeTdString function in server/runtime/storage/tdengine/index.js doubles single quotes but does not escape backslashes. A remote unauthenticated attacker can submit a crafted sids tag identifier through GET /api/daq or the
nvd
CVE-2026-47718P4MEDIUMCVSS 5.5v= 1.3.0-27732026-08-12
CVE-2026-47718 [MEDIUM] CWE-287 CVE-2026-47718: FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`,
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid-token requests to read project, alarms, and scheduler APIs. Version 1.3.1 fixes this issue.
nvd
CVE-2026-67442P4LOWCVSS 2.0fixed in 1.3.32026-08-18
CVE-2026-67442 [LOW] CWE-284 CVE-2026-67442: FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.3, DELETE /ap
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.3, DELETE /api/roles removes role definitions through server/runtime/users/usrstorage.js but does not remove the deleted role identifier from each user's info.roles array or the runtime usersMap cache. If a permission configuration still references that identifier, a
nvd
← Previous2 / 2