← Vulnerability feed

Vulnerability record · CVE-2026-25751 · published 6 February 2026

CVE-2026-25751: Frangoteam fuxa missing authentication for critical function vulnerability

Frangoteam · Fuxa

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An information disclosure vulnerability in FUXA allows an unauthenticated, remote attacker to retrieve sensitive administrative database credentials. Exploitation allows an unauthenticated, remote attacker to obtain the full system configuration, including administrative credentials for the InfluxDB database. Possession of these credentials may allow an attacker to authenticate directly to the database service, enabling them to read, modify, or delete all historical process data, or perform a Denial of Service by corrupting the database. This affects FUXA through version 1.2.9. This issue has been patched in FUXA version 1.2.10.

9.1 CVSS 4.0 Critical EPSS 0.38% · top 70.3% CWE-306 · Missing authentication for critical functionCWE-312 · Cleartext storage of sensitive data
9.1CVSS 4.0 base score
0.38%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An information disclosure vulnerability in FUXA allows an unauthenticated, remote attacker to retrieve sensitive administrative database credentials. Exploitation allows an unauthenticated, remote attacker to obtain the full system configuration, including administrative credentials for the InfluxDB database. Possession of these credentials may allow an attacker to authenticate directly to the database service, enabling them to read, modify, or delete all historical process data, or perform a Denial of Service by corrupting the database. This affects FUXA through version 1.2.9. This issue has been patched in FUXA version 1.2.10.

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-25751 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-25893Frangoteam fuxa improper authorization vulnerabilityFUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an u…EPSS 1.1%9.8CVE-2025-69985Frangoteam fuxa authentication bypass via alternate path vulnerabilityFUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/a…EPSS 5.7%9.8CVE-2025-69971Frangoteam fuxa hard-coded credentials vulnerabilityFUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-coded secret key to sign and veri…EPSS 2.1%9.8CVE-2025-69981Frangoteam fuxa unrestricted file upload vulnerabilityFUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks authentication mechanisms, allow…EPSS 0.77%9.8CVE-2025-69983Frangoteam fuxa code injection vulnerabilityFUXA v1.2.7 allows Remote Code Execution (RCE) via the project import functionality. The application does not properly sanitize or sandbox user-suppl…EPSS 0.44%9.8CVE-2023-31719Frangoteam fuxa sql injection vulnerabilityFUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin.EPSS 26%9.8CVE-2023-33831Frangoteam fuxa command injection vulnerabilityA remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a cra…EPSS 26%9.5CVE-2026-25938Frangoteam fuxa authentication bypass by spoofing vulnerabilityFUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA a…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2026-25751), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.