← Vulnerability feed

Vulnerability record · CVE-2025-69970 · published 3 February 2026

CVE-2025-69970: Frangoteam fuxa insecure default initialization vulnerability

Frangoteam · Fuxa

FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' flag is commented out by default, causing the application to initialize with authentication disabled. This allows unauthenticated remote attackers to access sensitive API endpoints, modify projects, and control industrial equipment immediately after installation.

9.3 CVSS 3.1 Critical EPSS 0.48% · top 60.9% CWE-1188 · Insecure default initialization
9.3CVSS 3.1 base score
0.48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' flag is commented out by default, causing the application to initialize with authentication disabled. This allows unauthenticated remote attackers to access sensitive API endpoints, modify projects, and control industrial equipment immediately after installation.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-69970 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-25893Frangoteam fuxa improper authorization vulnerabilityFUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an u…EPSS 1.1%9.8CVE-2025-69985Frangoteam fuxa authentication bypass via alternate path vulnerabilityFUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/a…EPSS 5.7%9.8CVE-2025-69971Frangoteam fuxa hard-coded credentials vulnerabilityFUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-coded secret key to sign and veri…EPSS 2.1%9.8CVE-2025-69981Frangoteam fuxa unrestricted file upload vulnerabilityFUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks authentication mechanisms, allow…EPSS 0.77%9.8CVE-2025-69983Frangoteam fuxa code injection vulnerabilityFUXA v1.2.7 allows Remote Code Execution (RCE) via the project import functionality. The application does not properly sanitize or sandbox user-suppl…EPSS 0.44%9.8CVE-2023-31719Frangoteam fuxa sql injection vulnerabilityFUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin.EPSS 26%9.8CVE-2023-33831Frangoteam fuxa command injection vulnerabilityA remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a cra…EPSS 26%9.5CVE-2026-25938Frangoteam fuxa authentication bypass by spoofing vulnerabilityFUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA a…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2025-69970), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.