
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69971 is a hard-coded credential vulnerability in FUXA v1.2.7, an open-source web-based SCADA/HMI application developed by frangoteam. The flaw resides in server/api/jwt-helper.js, where the application uses a static, hard-coded secret key to sign and verify JSON Web Tokens (JWTs). This allows unauthenticated remote attackers to forge valid admin tokens and gain full administrative access without any credentials. The vulnerability was published on February 3, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical) (Red Hat CVE, FUXA Source).
The root cause is classified as CWE-798 (Use of Hard-coded Credentials). In server/api/jwt-helper.js, the application initializes a secretCode variable using utils.generateSecretCode() as a fallback, but the init() function accepts an externally supplied _secretCode parameter — and in v1.2.7, a static hard-coded value is used in practice to sign and verify all JWTs. Because the secret is known or extractable from the source code, any attacker can craft a JWT with id and groups fields set to admin values (e.g., group -1 or 255, which are defined as adminGroups) and sign it with the known secret. The forged token will pass the jwt.verify() check in requireAuth and verifyToken, granting full administrative access over the network with no user interaction required (FUXA Source, Infinit Security).
Successful exploitation grants an unauthenticated remote attacker complete administrative control over the affected FUXA instance. This results in high confidentiality, integrity, and availability impact — attackers can read all application data, modify SCADA/HMI configurations, disrupt industrial process monitoring, and potentially pivot to connected operational technology (OT) or IT systems. Given FUXA's role as an industrial SCADA/HMI platform, compromise could have significant consequences for operational environments (Red Hat CVE, Infinit Security).
No public proof-of-concept exploit code has been confirmed, and there is no evidence of active in-the-wild exploitation at this time (Red Hat CVE). However, the vulnerability has been detected by Qualys scanners and nuclei templates for automated detection have been added to the ProjectDiscovery nuclei-templates repository across multiple commits, significantly lowering the barrier for exploitation (nuclei-templates). The EPSS score is approximately 0.053%, reflecting low but non-zero probability of exploitation in the near term. The CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
server/api/jwt-helper.js.jsonwebtoken, Python PyJWT), craft a token with admin group membership: { "id": "admin", "groups": [-1] } and sign it with the extracted hard-coded secret key.x-access-token HTTP header when making API requests to the FUXA instance. The server's requireAuth middleware will validate the token and grant admin-level access./api/) from unknown or external IP addresses containing a valid x-access-token header without a prior login event; unusual outbound connections from the FUXA server host.No official vendor patch has been confirmed for v1.2.7 at the time of this report. Organizations should immediately inventory all FUXA deployments and restrict network access to FUXA instances using firewalls or network segmentation, allowing only trusted hosts. As a workaround, administrators should configure FUXA with a strong, randomly generated JWT secret via the init() function's _secretCode parameter rather than relying on any default or hard-coded value. Monitor JWT token usage for anomalous admin authentication patterns and consider placing an API gateway or reverse proxy with additional authentication in front of FUXA until a patched version is available (Red Hat CVE, Infinit Security).
The vulnerability received coverage from security researchers and automated vulnerability tracking platforms shortly after disclosure. A technical write-up was published by Infinit Security detailing the flaw (Infinit Security). The ProjectDiscovery community added multiple nuclei detection templates for this CVE, indicating active interest from the security research community (nuclei-templates). Social media discussion was noted on Bluesky from security-focused accounts. Red Hat also tracked the vulnerability in their CVE database, though no Red Hat products are directly affected.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."