« Volver al listado

Frangoteam

Frangoteam Fuxa: vulnerabilidades y CVE

Frangoteam Fuxa tiene 33 vulnerabilidades publicadas, 27 de ellas en los últimos 12 meses. 15 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE33
Últimos 12 meses27
Críticas15
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-67442Baja (2)0.32%—18 ago 2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.3, DELETE /api/roles removes role definitions through server/runtime/users/usrstorage.js but does not remove the deleted role…
CVE-2026-67443Crítica (9.2)0.69%—18 ago 2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the allowDashboard authorization gate in server/integrations/node-red/index.js calls authJwt.verify for /nodered without…
CVE-2026-67440Media (6.9)0.54%—18 ago 2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the DEVICE_BROWSE, DEVICE_NODE_ATTRIBUTE, HOST_INTERFACES, and DEVICE_TAGS_REQUEST handlers in server/runtime/index.js…
CVE-2026-65985Media (6)0.46%—18 ago 2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the device-webapi-request Socket.IO handler in server/runtime/index.js permits an authenticated non-admin runtime user to…
CVE-2026-65984Alta (7.5)0.52%—18 ago 2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, POST /api/refresh in server/api/auth/index.js falls back from current user data to decoded.groups, including when the user…
CVE-2026-47721Media (6.3)0.43%—18 ago 2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/scheduler and DELETE /api/scheduler in server/api/scheduler/index.js do not consistently enforce…
CVE-2026-47720Media (5.3)0.64%—18 ago 2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengine DAQ storage connector's escapeTdString function in server/runtime/storage/tdengine/index.js doubles single quotes…
CVE-2026-47719Alta (8.2)0.59%—18 ago 2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY Socket.IO handlers in server/runtime/index.js omit isSocketWriteAuthorized and…
CVE-2026-47718Media (5.5)0.46%—12 ago 2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid-token requests to read project, alarms, and scheduler APIs. Version…
CVE-2026-72586Alta (7.5)0.63%—10 ago 2026
A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated remote attacker to query all historical sensor data via the DAQ_QUERY Socket.IO event. When secureEnabled=true, all other…
CVE-2026-43947Alta (8.9)0.91%—21 jul 2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an unauthenticated Remote Code Execution vulnerability when `secureEnabled` is set to `true`. The `POST /api/runscript`…
CVE-2026-43946Alta (7.7)0.57%—21 jul 2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an authorization bypass in the /api/getTagValue endpoint allows unauthenticated access to tag values when the referenced script…
CVE-2026-43945Alta (8.9)0.84%—21 jul 2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to achieve Full Remote Code Execution (RCE) as root. The exploit succeeds…
CVE-2026-13207Alta (8.7)0.61%—30 jun 2026
FUXA versions 1.3.1 and prior contain an authentication bypass vulnerability via dot-segment path normalization in the REST API. The API router fails to normalize dot-segment sequences before applying authentication…
CVE-2025-69985Crítica (9.8)5.7%—24 feb 2026
FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trusts the HTTP…
CVE-2026-25951Alta (8.6)1.8%—9 feb 2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.11, there is a flaw in the path sanitization logic allows an authenticated attacker with administrative privileges to bypass…
CVE-2026-25939Crítica (9.3)0.86%—9 feb 2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authorization bypass vulnerability in the FUXA allows an unauthenticated, remote attacker to create and…
CVE-2026-25938Crítica (9.5)1.4%—9 feb 2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to execute arbitrary code on…
CVE-2026-25895Crítica (9.5)6.3%—9 feb 2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locations on the server…
CVE-2026-25894Crítica (9.5)1.3%—9 feb 2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An insecure default configuration in FUXA allows an unauthenticated, remote attacker to gain administrative access and execute arbitrary code on…
CVE-2026-25893Crítica (10)1.1%—9 feb 2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to gain administrative access via the…
CVE-2026-25752Crítica (9.3)0.68%—6 feb 2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An authorization bypass vulnerability in FUXA allows an unauthenticated, remote attacker to modify device tags via WebSockets. Exploitation…
CVE-2026-25751Crítica (9.1)0.38%—6 feb 2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An information disclosure vulnerability in FUXA allows an unauthenticated, remote attacker to retrieve sensitive administrative database…
CVE-2025-69983Crítica (9.8)0.48%—3 feb 2026
FUXA v1.2.7 allows Remote Code Execution (RCE) via the project import functionality. The application does not properly sanitize or sandbox user-supplied scripts within imported project files. An attacker can upload a…
CVE-2025-69981Crítica (9.8)0.82%—3 feb 2026
FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks authentication mechanisms, allowing unauthenticated remote attackers to upload arbitrary files. This…
CVE-2025-69971Crítica (9.8)2.2%—3 feb 2026
FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-coded secret key to sign and verify JWT Tokens. This allows remote attackers to forge valid admin…
CVE-2025-69970Crítica (9.3)0.52%—3 feb 2026
FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' flag is commented out by default, causing the application to initialize with authentication…
CVE-2023-31719Crítica (9.8)26%—22 sept 2023
FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin.
CVE-2023-31718Alta (7.5)1.7%—22 sept 2023
FUXA <= 1.1.12 is vulnerable to Local via Inclusion via /api/download.
CVE-2023-31717Alta (7.5)1.8%—22 sept 2023
A SQL Injection attack in FUXA <= 1.1.12 allows exfiltration of confidential information from the database.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application18
  2. T1078 Valid Accounts8
  3. T1059 Command and Scripting Interpreter4
  4. T1078.001 Default Accounts2
  5. T1210 Exploitation of Remote Services2
  6. T1005 Data from Local System1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.