Frangoteam
Frangoteam Fuxa: vulnerabilidades y CVE
Frangoteam Fuxa tiene 33 vulnerabilidades publicadas, 27 de ellas en los últimos 12 meses. 15 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE33
Últimos 12 meses27
Críticas15
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-67442 | Baja (2) | 0.32% | — | 18 ago 2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.3, DELETE /api/roles removes role definitions through server/runtime/users/usrstorage.js but does not remove the deleted role… |
| CVE-2026-67443 | Crítica (9.2) | 0.69% | — | 18 ago 2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the allowDashboard authorization gate in server/integrations/node-red/index.js calls authJwt.verify for /nodered without… |
| CVE-2026-67440 | Media (6.9) | 0.54% | — | 18 ago 2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the DEVICE_BROWSE, DEVICE_NODE_ATTRIBUTE, HOST_INTERFACES, and DEVICE_TAGS_REQUEST handlers in server/runtime/index.js… |
| CVE-2026-65985 | Media (6) | 0.46% | — | 18 ago 2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the device-webapi-request Socket.IO handler in server/runtime/index.js permits an authenticated non-admin runtime user to… |
| CVE-2026-65984 | Alta (7.5) | 0.52% | — | 18 ago 2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, POST /api/refresh in server/api/auth/index.js falls back from current user data to decoded.groups, including when the user… |
| CVE-2026-47721 | Media (6.3) | 0.43% | — | 18 ago 2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/scheduler and DELETE /api/scheduler in server/api/scheduler/index.js do not consistently enforce… |
| CVE-2026-47720 | Media (5.3) | 0.64% | — | 18 ago 2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengine DAQ storage connector's escapeTdString function in server/runtime/storage/tdengine/index.js doubles single quotes… |
| CVE-2026-47719 | Alta (8.2) | 0.59% | — | 18 ago 2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY Socket.IO handlers in server/runtime/index.js omit isSocketWriteAuthorized and… |
| CVE-2026-47718 | Media (5.5) | 0.46% | — | 12 ago 2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid-token requests to read project, alarms, and scheduler APIs. Version… |
| CVE-2026-72586 | Alta (7.5) | 0.63% | — | 10 ago 2026 | A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated remote attacker to query all historical sensor data via the DAQ_QUERY Socket.IO event. When secureEnabled=true, all other… |
| CVE-2026-43947 | Alta (8.9) | 0.91% | — | 21 jul 2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an unauthenticated Remote Code Execution vulnerability when `secureEnabled` is set to `true`. The `POST /api/runscript`… |
| CVE-2026-43946 | Alta (7.7) | 0.57% | — | 21 jul 2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an authorization bypass in the /api/getTagValue endpoint allows unauthenticated access to tag values when the referenced script… |
| CVE-2026-43945 | Alta (8.9) | 0.84% | — | 21 jul 2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to achieve Full Remote Code Execution (RCE) as root. The exploit succeeds… |
| CVE-2026-13207 | Alta (8.7) | 0.61% | — | 30 jun 2026 | FUXA versions 1.3.1 and prior contain an authentication bypass vulnerability via dot-segment path normalization in the REST API. The API router fails to normalize dot-segment sequences before applying authentication… |
| CVE-2025-69985 | Crítica (9.8) | 5.7% | — | 24 feb 2026 | FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trusts the HTTP… |
| CVE-2026-25951 | Alta (8.6) | 1.8% | — | 9 feb 2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.11, there is a flaw in the path sanitization logic allows an authenticated attacker with administrative privileges to bypass… |
| CVE-2026-25939 | Crítica (9.3) | 0.86% | — | 9 feb 2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authorization bypass vulnerability in the FUXA allows an unauthenticated, remote attacker to create and… |
| CVE-2026-25938 | Crítica (9.5) | 1.4% | — | 9 feb 2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to execute arbitrary code on… |
| CVE-2026-25895 | Crítica (9.5) | 6.3% | — | 9 feb 2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locations on the server… |
| CVE-2026-25894 | Crítica (9.5) | 1.3% | — | 9 feb 2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An insecure default configuration in FUXA allows an unauthenticated, remote attacker to gain administrative access and execute arbitrary code on… |
| CVE-2026-25893 | Crítica (10) | 1.1% | — | 9 feb 2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to gain administrative access via the… |
| CVE-2026-25752 | Crítica (9.3) | 0.68% | — | 6 feb 2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An authorization bypass vulnerability in FUXA allows an unauthenticated, remote attacker to modify device tags via WebSockets. Exploitation… |
| CVE-2026-25751 | Crítica (9.1) | 0.38% | — | 6 feb 2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An information disclosure vulnerability in FUXA allows an unauthenticated, remote attacker to retrieve sensitive administrative database… |
| CVE-2025-69983 | Crítica (9.8) | 0.48% | — | 3 feb 2026 | FUXA v1.2.7 allows Remote Code Execution (RCE) via the project import functionality. The application does not properly sanitize or sandbox user-supplied scripts within imported project files. An attacker can upload a… |
| CVE-2025-69981 | Crítica (9.8) | 0.82% | — | 3 feb 2026 | FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks authentication mechanisms, allowing unauthenticated remote attackers to upload arbitrary files. This… |
| CVE-2025-69971 | Crítica (9.8) | 2.2% | — | 3 feb 2026 | FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-coded secret key to sign and verify JWT Tokens. This allows remote attackers to forge valid admin… |
| CVE-2025-69970 | Crítica (9.3) | 0.52% | — | 3 feb 2026 | FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' flag is commented out by default, causing the application to initialize with authentication… |
| CVE-2023-31719 | Crítica (9.8) | 26% | — | 22 sept 2023 | FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin. |
| CVE-2023-31718 | Alta (7.5) | 1.7% | — | 22 sept 2023 | FUXA <= 1.1.12 is vulnerable to Local via Inclusion via /api/download. |
| CVE-2023-31717 | Alta (7.5) | 1.8% | — | 22 sept 2023 | A SQL Injection attack in FUXA <= 1.1.12 allows exfiltration of confidential information from the database. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.