CVE-2026-43945 PUBLISHED

FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection

Assigner: GitHub_M
Reserved: 04.05.2026 Published: 21.07.2026 Updated: 21.07.2026

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to achieve Full Remote Code Execution (RCE) as root. The exploit succeeds even when the platform is configured in its most secure state (Secure Mode Enabled and Node-RED Secure Auth Enabled). Version 1.3.1 fixes the issue.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
CVSS Score: 8.9

Product Status

Vendor frangoteam
Product FUXA
Versions
  • Version >= 1.2.11, < 1.3.1 is affected

References

Problem Types

  • CWE-94: Improper Control of Generation of Code ('Code Injection') CWE
  • CWE-284: Improper Access Control CWE
  • CWE-288: Authentication Bypass Using an Alternate Path or Channel CWE
  • CWE-863: Incorrect Authorization CWE