Логотип exploitDog
bind:CVE-2025-69970
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-69970

Количество 2

Количество 2

nvd логотип

CVE-2025-69970

5 дней назад

FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' flag is commented out by default, causing the application to initialize with authentication disabled. This allows unauthenticated remote attackers to access sensitive API endpoints, modify projects, and control industrial equipment immediately after installation.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-r5m2-fqcf-qrf7

5 дней назад

FUXA contains an insecure default configuration vulnerability

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-69970

FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' flag is commented out by default, causing the application to initialize with authentication disabled. This allows unauthenticated remote attackers to access sensitive API endpoints, modify projects, and control industrial equipment immediately after installation.

CVSS3: 9.3
0%
Низкий
5 дней назад
github логотип
GHSA-r5m2-fqcf-qrf7

FUXA contains an insecure default configuration vulnerability

0%
Низкий
5 дней назад

Уязвимостей на страницу