VYPR

Fuxa

by Frangoteam

Source repositories

CVEs (29)

  • CVE-2021-45851HigMar 16, 2022
    risk 0.49cvss 7.5epss 0.01

    A Server-Side Request Forgery (SSRF) attack in FUXA 1.1.3 can be carried out leading to the obtaining of sensitive information from the server's internal environment and services, often potentially leading to the attacker executing commands on the server.

  • CVE-2026-47719higJun 8, 2026
    risk 0.45cvss epss 0.00

    ## Summary An unauthenticated attacker (Alice) connects to FUXA's Socket.IO endpoint and emits a `device-webapi-request` event whose `property.address` field names an arbitrary URL. FUXA's `DEVICE_WEBAPI_REQUEST` handler at `server/runtime/index.js:296` calls…

  • CVE-2026-43946HigJul 21, 2026
    risk 0.43cvss epss 0.01

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an authorization bypass in the /api/getTagValue endpoint allows unauthenticated access to tag values when the referenced script does not exist. Version 1.3.1 patches the issue.

  • CVE-2026-47717HigAug 12, 2026
    risk 0.42cvss 7.5epss 0.01

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. Version 1.3.1 fixes the issue.

  • CVE-2026-25751HigFeb 6, 2026
    risk 0.42cvss 7.5epss 0.00

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An information disclosure vulnerability in FUXA allows an unauthenticated, remote attacker to retrieve sensitive administrative database credentials. Exploitation allows an unauthenticated, remote attacker…

  • CVE-2026-25951HigFeb 9, 2026
    risk 0.40cvss 7.2epss 0.01

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.11, there is a flaw in the path sanitization logic allows an authenticated attacker with administrative privileges to bypass directory traversal protections. By using nested traversal…

  • CVE-2026-47718MedAug 12, 2026
    risk 0.29cvss epss 0.00

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid-token requests to read project, alarms, and scheduler APIs. Version 1.3.1 fixes this issue.

  • CVE-2026-47721Jun 8, 2026
    risk 0.00cvss epss 0.00

    ## Summary An authorization issue in the Scheduler API allowed authenticated non-admin users to create or modify scheduled actions that should be restricted to administrators. ## Details The Scheduler API did not correctly enforce administrator permissions when processing…

  • CVE-2026-47720Jun 8, 2026
    risk 0.00cvss epss 0.00

    ## Summary The TDengine DAQ storage connector's `escapeTdString` at `server/runtime/storage/tdengine/index.js:10` doubles single quotes but does not escape backslashes. TDengine's SQL parser treats `\'` as a literal single quote inside a string, so a tag id of the form `x\' OR…

Page 2 of 2