← Vulnerability feed

Vulnerability record · CVE-2026-25894 · published 9 February 2026

CVE-2026-25894: Frangoteam fuxa insecure default initialization vulnerability

Frangoteam · Fuxa

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An insecure default configuration in FUXA allows an unauthenticated, remote attacker to gain administrative access and execute arbitrary code on the server. This affects FUXA through version 1.2.9 when authentication is enabled, but the administrator JWT secret is not configured. This issue has been patched in FUXA version 1.2.10.

9.5 CVSS 4.0 Critical EPSS 1.2% · top 32.0% CWE-321 · CWE-321CWE-1188 · Insecure default initialization
9.5CVSS 4.0 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An insecure default configuration in FUXA allows an unauthenticated, remote attacker to gain administrative access and execute arbitrary code on the server. This affects FUXA through version 1.2.9 when authentication is enabled, but the administrator JWT secret is not configured. This issue has been patched in FUXA version 1.2.10.

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-25894 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-25893Frangoteam fuxa improper authorization vulnerabilityFUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an u…EPSS 1.1%9.8CVE-2025-69985Frangoteam fuxa authentication bypass via alternate path vulnerabilityFUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/a…EPSS 5.7%9.8CVE-2025-69971Frangoteam fuxa hard-coded credentials vulnerabilityFUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-coded secret key to sign and veri…EPSS 2.1%9.8CVE-2025-69981Frangoteam fuxa unrestricted file upload vulnerabilityFUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks authentication mechanisms, allow…EPSS 0.77%9.8CVE-2025-69983Frangoteam fuxa code injection vulnerabilityFUXA v1.2.7 allows Remote Code Execution (RCE) via the project import functionality. The application does not properly sanitize or sandbox user-suppl…EPSS 0.44%9.8CVE-2023-31719Frangoteam fuxa sql injection vulnerabilityFUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin.EPSS 26%9.8CVE-2023-33831Frangoteam fuxa command injection vulnerabilityA remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a cra…EPSS 26%9.5CVE-2026-25938Frangoteam fuxa authentication bypass by spoofing vulnerabilityFUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA a…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2026-25894), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.