PT-2026-6662 · Fuxa · Fuxa

Wodzen

·

Published

2026-02-05

·

Updated

2026-02-10

·

CVE-2026-25752

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions FUXA versions through 1.2.9
Description FUXA is a web-based Process Visualization software. An authorization bypass allows a remote attacker to modify device tags via WebSockets. Exploitation bypasses role-based access controls, enabling attackers to overwrite device tags or disable communication drivers, potentially manipulating physical processes and disconnected devices. The runtime.settings.secureEnabled setting does not prevent exploitation.
Recommendations Update to version 1.2.10 or later.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-25752
GHSA-GGXW-G3CP-MGF8

Affected Products

Fuxa