CVE-2025-69971: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2025-69971 is a hard-coded credential vulnerability in FUXA v1.2.7, an open-source web-based SCADA/HMI application developed by frangoteam. The flaw resides in server/api/jwt-helper.js, where the application uses a static, hard-coded secret key to sign and verify JSON Web Tokens (JWTs). This allows unauthenticated remote attackers to forge valid admin tokens and gain full administrative access without any credentials. The vulnerability was published on February 3, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical) (Red Hat CVE, FUXA Source).

Technical details

The root cause is classified as CWE-798 (Use of Hard-coded Credentials). In server/api/jwt-helper.js, the application initializes a secretCode variable using utils.generateSecretCode() as a fallback, but the init() function accepts an externally supplied _secretCode parameter — and in v1.2.7, a static hard-coded value is used in practice to sign and verify all JWTs. Because the secret is known or extractable from the source code, any attacker can craft a JWT with id and groups fields set to admin values (e.g., group -1 or 255, which are defined as adminGroups) and sign it with the known secret. The forged token will pass the jwt.verify() check in requireAuth and verifyToken, granting full administrative access over the network with no user interaction required (FUXA Source, Infinit Security).

Impact

Successful exploitation grants an unauthenticated remote attacker complete administrative control over the affected FUXA instance. This results in high confidentiality, integrity, and availability impact — attackers can read all application data, modify SCADA/HMI configurations, disrupt industrial process monitoring, and potentially pivot to connected operational technology (OT) or IT systems. Given FUXA's role as an industrial SCADA/HMI platform, compromise could have significant consequences for operational environments (Red Hat CVE, Infinit Security).

Exploitability

No public proof-of-concept exploit code has been confirmed, and there is no evidence of active in-the-wild exploitation at this time (Red Hat CVE). However, the vulnerability has been detected by Qualys scanners and nuclei templates for automated detection have been added to the ProjectDiscovery nuclei-templates repository across multiple commits, significantly lowering the barrier for exploitation (nuclei-templates). The EPSS score is approximately 0.053%, reflecting low but non-zero probability of exploitation in the near term. The CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible FUXA v1.2.7 instances using tools like Shodan, Censys, or the ProjectDiscovery nuclei scanner with the available template.
  2. Extract the hard-coded secret: Obtain the hard-coded JWT secret key from the publicly available FUXA v1.2.7 source code in server/api/jwt-helper.js.
  3. Forge an admin JWT: Using any JWT library (e.g., Node.js jsonwebtoken, Python PyJWT), craft a token with admin group membership: { "id": "admin", "groups": [-1] } and sign it with the extracted hard-coded secret key.
  4. Send authenticated request: Include the forged token in the x-access-token HTTP header when making API requests to the FUXA instance. The server's requireAuth middleware will validate the token and grant admin-level access.
  5. Achieve full administrative control: With admin access, interact with all FUXA API endpoints to read/modify SCADA configurations, extract sensitive data, create new users, or disrupt monitored industrial processes (FUXA Source, Infinit Security).

Indicators of compromise

  • Network: Unexpected HTTP requests to FUXA API endpoints (e.g., /api/) from unknown or external IP addresses containing a valid x-access-token header without a prior login event; unusual outbound connections from the FUXA server host.
  • Logs: FUXA application logs showing admin-level API actions (configuration changes, user creation) with no corresponding login event or from unexpected source IPs; JWT tokens in access logs that were not issued by the server's own login flow.
  • Process/Behavior: Unexpected changes to SCADA/HMI configurations, new user accounts created in FUXA, or modifications to device/tag definitions without corresponding authorized user activity.
  • File System: Presence of nuclei scanner output files or automated scanning artifacts on systems that have probed the FUXA instance.

Mitigation and workarounds

No official vendor patch has been confirmed for v1.2.7 at the time of this report. Organizations should immediately inventory all FUXA deployments and restrict network access to FUXA instances using firewalls or network segmentation, allowing only trusted hosts. As a workaround, administrators should configure FUXA with a strong, randomly generated JWT secret via the init() function's _secretCode parameter rather than relying on any default or hard-coded value. Monitor JWT token usage for anomalous admin authentication patterns and consider placing an API gateway or reverse proxy with additional authentication in front of FUXA until a patched version is available (Red Hat CVE, Infinit Security).

Community reactions

The vulnerability received coverage from security researchers and automated vulnerability tracking platforms shortly after disclosure. A technical write-up was published by Infinit Security detailing the flaw (Infinit Security). The ProjectDiscovery community added multiple nuclei detection templates for this CVE, indicating active interest from the security research community (nuclei-templates). Social media discussion was noted on Bluesky from security-focused accounts. Red Hat also tracked the vulnerability in their CVE database, though no Red Hat products are directly affected.

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management