PT-2026-7183 · Fuxa · Fuxa

Wodzen

·

Published

2026-02-09

·

Updated

2026-03-03

·

CVE-2026-25939

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions FUXA versions 1.2.8 through 1.2.10
Description FUXA is a web-based Process Visualization software used in SCADA/HMI/Dashboard systems. An authorization bypass allows a remote, unauthenticated attacker to create and modify schedulers. This can expose connected ICS/SCADA environments to further malicious actions. The vulnerability exists due to insufficient access controls.
Recommendations Update to FUXA version 1.2.11 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25939
GHSA-C869-JX4C-Q5FC

Affected Products

Fuxa