Количество 2
Количество 2
CVE-2026-25894
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An insecure default configuration in FUXA allows an unauthenticated, remote attacker to gain administrative access and execute arbitrary code on the server. This affects FUXA through version 1.2.9 when authentication is enabled, but the administrator JWT secret is not configured. This issue has been patched in FUXA version 1.2.10.
GHSA-32cc-x95p-fxcg
FUXA Unauthenticated Remote Code Execution via Hardcoded JWT Secret in Default Configuration
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-25894 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An insecure default configuration in FUXA allows an unauthenticated, remote attacker to gain administrative access and execute arbitrary code on the server. This affects FUXA through version 1.2.9 when authentication is enabled, but the administrator JWT secret is not configured. This issue has been patched in FUXA version 1.2.10. | CVSS3: 9.8 | 1% Низкий | 6 месяцев назад | |
GHSA-32cc-x95p-fxcg FUXA Unauthenticated Remote Code Execution via Hardcoded JWT Secret in Default Configuration | 1% Низкий | 6 месяцев назад |
Уязвимостей на страницу