
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25752 is an authorization bypass vulnerability in FUXA, a web-based Process Visualization (SCADA/HMI/Dashboard) software developed by frangoteam, that allows unauthenticated remote attackers to modify arbitrary device tags via WebSockets. The vulnerability affects all FUXA deployments through version 1.2.9, including those with runtime.settings.secureEnabled set to true. It was published on February 4, 2026, and patched in version 1.2.10. It carries a CVSS v3.1 base score of 9.1 (Critical) and a CVSS v4.0 base score of 9.3 (Critical) (GitHub Advisory, FUXA Security Advisory).
The root cause is CWE-862 (Missing Authorization): FUXA fails to perform authorization checks when actors attempt to access or modify device tags via its WebSocket interface, meaning even unauthenticated connections can issue privileged commands. This flaw bypasses role-based access controls entirely, including when security mode (secureEnabled) is active. An attacker can connect to the FUXA WebSocket endpoint without credentials and send crafted messages to overwrite arbitrary device tags or disable communication drivers. The fix in v1.2.10 addressed this by enforcing authentication and hardening validation for relevant request handling, including a fix for an authentication bypass related to heartbeat token refresh (FUXA Security Advisory, FUXA v1.2.10 Release).
Successful exploitation allows an unauthenticated remote attacker to overwrite arbitrary device tags or disable communication drivers in ICS/SCADA environments managed by FUXA, with high integrity and availability impact on both the vulnerable system and downstream industrial systems. Attackers could manipulate physical processes controlled by connected devices or disconnect devices from the HMI entirely, potentially causing operational disruption or unsafe physical conditions. Confidentiality impact is assessed as low, as the primary risk is unauthorized modification and disruption rather than data exfiltration (GitHub Advisory, FUXA Security Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (GitHub Advisory). The vulnerability requires no authentication, no user interaction, and no special preconditions, making it trivially exploitable by any network-accessible attacker. The EPSS score is approximately 0.021% (6th percentile), indicating a currently low but non-negligible probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability is not currently listed in the CISA KEV catalog.
ws://<target>:<port>/) without providing any authentication credentials, as the server does not enforce authorization checks on this interface.runtime.settings.secureEnabled is set to true.The primary remediation is to upgrade FUXA to version 1.2.10 or later, which fixes the authentication bypass related to heartbeat token refresh, enforces authentication on WebSocket and file upload endpoints, and hardens JWT secret handling (FUXA v1.2.10 Release, FUXA Security Advisory). As an interim workaround, restrict network access to FUXA systems at the firewall or network segmentation level to prevent unauthenticated external connections to the WebSocket interface. Monitor WebSocket connections for unauthorized access attempts while patching is in progress.
The vulnerability was reported by researcher wodzen and published by the FUXA maintainer unocelli on February 4, 2026, with a patch released simultaneously in v1.2.10. The advisory received attention on Mastodon via The Hacker Wire and was indexed by multiple vulnerability tracking platforms shortly after disclosure. No major vendor statements beyond the official GitHub advisory or significant media coverage have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."