
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69983 is a Remote Code Execution (RCE) vulnerability in FUXA v1.2.7, an open-source web-based SCADA/HMI application developed by frangoteam. The flaw exists in the project import functionality, where user-supplied scripts within imported project files are neither sanitized nor sandboxed, allowing an attacker to upload a malicious project file containing arbitrary system commands. It was published on February 3, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical) (Red Hat CVE, Feedly).
The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection). The vulnerable code resides in server/api/projects/index.js, where the /api/project POST endpoint accepts project data and passes it to runtime.project.setProject() followed by runtime.restart() without adequately validating or sandboxing embedded scripts (FUXA GitHub). An attacker can craft a malicious FUXA project file containing embedded system commands that are executed server-side upon import. The CVSS vector indicates no authentication, no user interaction, and low attack complexity are required, making this trivially exploitable over the network (Red Hat CVE).
Successful exploitation grants an unauthenticated remote attacker full system compromise on the host running FUXA. This includes unauthorized access to sensitive data (confidentiality impact: HIGH), modification or destruction of system files and project data (integrity impact: HIGH), and potential disruption of SCADA/HMI operations (availability impact: HIGH). Given FUXA's use in industrial control and automation environments, exploitation could have operational technology (OT) consequences beyond the server itself (Red Hat CVE, Feedly).
As of the time of reporting, no public proof-of-concept exploit code has been observed, and there is no confirmed evidence of in-the-wild exploitation (Feedly). The vulnerability has been detected by Qualys (detection ID 5007424) and is listed in the GitLab advisory database for the fuxa-server npm package (GitLab Advisory). The EPSS score is approximately 0.058% (0.000580), indicating a currently low but non-negligible probability of exploitation in the near term. No CISA KEV catalog listing or threat actor attribution has been identified at this time.
fuxa or the default FUXA HTTP port) or by scanning internal OT/ICS networks.child_process.exec() calls or OS command strings) within script fields that FUXA evaluates upon project load./api/project endpoint with the malicious project payload. If the endpoint requires authentication in the target deployment, attempt default or weak credentials first.runtime.project.setProject() with the attacker-controlled data, then invokes runtime.restart(), causing the embedded malicious scripts to be evaluated and executed in the server's Node.js runtime context without sandboxing./api/project from untrusted or external IP addresses; outbound connections from the FUXA server process to unknown external hosts (potential reverse shell or C2 traffic).api post project) from unusual sources or at unusual times; Node.js error traces related to script evaluation in project loading routines.sh, bash, cmd.exe, powershell, curl, wget, nc); unexpected network listeners created by child processes of the FUXA service.~/.fuxa/) not associated with normal project saves; presence of web shells, cron jobs, or scheduled tasks created by the FUXA service account.No official vendor patch has been confirmed as available at the time of this report. Recommended interim mitigations include: (1) restricting network access to the FUXA web interface to trusted hosts only using firewall rules; (2) requiring strong authentication for all FUXA API endpoints and disabling unauthenticated access; (3) running FUXA with a least-privilege service account to limit the blast radius of exploitation; (4) sandboxing or containerizing FUXA deployments (e.g., Docker with restricted capabilities); and (5) monitoring for suspicious project import activity and unexpected child process execution. Organizations should monitor the FUXA GitHub repository and vendor communications for patch releases and apply them immediately upon availability (Red Hat CVE, Feedly).
Red Hat has published a CVE tracking page for CVE-2025-69983, indicating awareness within the broader security community (Red Hat CVE). The GitLab advisory database has also catalogued the vulnerability for the fuxa-server npm package (GitLab Advisory). No significant public researcher commentary, vendor statements from frangoteam, or notable media coverage has been identified beyond standard vulnerability database entries at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."