Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r5m2-fqcf-qrf7

Опубликовано: 03 фев. 2026
Источник: github
Github: Прошло ревью
CVSS4: 8

Описание

FUXA contains an insecure default configuration vulnerability

FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' flag is commented out by default, causing the application to initialize with authentication disabled. This allows unauthenticated remote attackers to access sensitive API endpoints, modify projects, and control industrial equipment immediately after installation.

Пакеты

Наименование

fuxa-server

npm
Затронутые версииВерсия исправления

<= 1.2.7

Отсутствует

EPSS

Процентиль: 15%
0.00049
Низкий

8 High

CVSS4

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 9.3
nvd
4 дня назад

FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' flag is commented out by default, causing the application to initialize with authentication disabled. This allows unauthenticated remote attackers to access sensitive API endpoints, modify projects, and control industrial equipment immediately after installation.

EPSS

Процентиль: 15%
0.00049
Низкий

8 High

CVSS4

Дефекты

CWE-306