PT-2026-6662 · Fuxa · Fuxa

·

CVE-2026-25752

·

Published

2026-02-05

·

Updated

2026-02-10

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions FUXA versions through 1.2.9
Description FUXA is a web-based Process Visualization software. An authorization bypass allows a remote attacker to modify device tags via WebSockets. Exploitation bypasses role-based access controls, enabling attackers to overwrite device tags or disable communication drivers, potentially manipulating physical processes and disconnected devices. The runtime.settings.secureEnabled setting does not prevent exploitation.
Recommendations Update to version 1.2.10 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25752
GHSA-GGXW-G3CP-MGF8

Affected Products

Fuxa