Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-69970

Опубликовано: 03 фев. 2026
Источник: nvd
CVSS3: 9.3
EPSS Низкий

Описание

FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' flag is commented out by default, causing the application to initialize with authentication disabled. This allows unauthenticated remote attackers to access sensitive API endpoints, modify projects, and control industrial equipment immediately after installation.

EPSS

Процентиль: 15%
0.00049
Низкий

9.3 Critical

CVSS3

Дефекты

CWE-79

Связанные уязвимости

github
4 дня назад

FUXA contains an insecure default configuration vulnerability

EPSS

Процентиль: 15%
0.00049
Низкий

9.3 Critical

CVSS3

Дефекты

CWE-79