← Vulnerability feed

Vulnerability record · CVE-2026-25938 · published 9 February 2026

CVE-2026-25938: Frangoteam fuxa authentication bypass by spoofing vulnerability

Frangoteam · Fuxa

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to execute arbitrary code on the server when the Node-RED plugin is enabled. This has been patched in FUXA version 1.2.11.

9.5 CVSS 4.0 Critical EPSS 1.3% · top 30.1% CWE-290 · Authentication bypass by spoofingCWE-306 · Missing authentication for critical function
9.5CVSS 4.0 base score
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to execute arbitrary code on the server when the Node-RED plugin is enabled. This has been patched in FUXA version 1.2.11.

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-25938 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-25893Frangoteam fuxa improper authorization vulnerabilityFUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an u…EPSS 1.1%9.8CVE-2025-69985Frangoteam fuxa authentication bypass via alternate path vulnerabilityFUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/a…EPSS 5.7%9.8CVE-2025-69971Frangoteam fuxa hard-coded credentials vulnerabilityFUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-coded secret key to sign and veri…EPSS 2.1%9.8CVE-2025-69981Frangoteam fuxa unrestricted file upload vulnerabilityFUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks authentication mechanisms, allow…EPSS 0.77%9.8CVE-2025-69983Frangoteam fuxa code injection vulnerabilityFUXA v1.2.7 allows Remote Code Execution (RCE) via the project import functionality. The application does not properly sanitize or sandbox user-suppl…EPSS 0.44%9.8CVE-2023-31719Frangoteam fuxa sql injection vulnerabilityFUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin.EPSS 26%9.8CVE-2023-33831Frangoteam fuxa command injection vulnerabilityA remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a cra…EPSS 26%9.5CVE-2026-25894Frangoteam fuxa insecure default initialization vulnerabilityFUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An insecure default configuration in FUXA allows an unauthenticated, remote…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2026-25938), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.