CVE-2026-25752: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-25752 is an authorization bypass vulnerability in FUXA, a web-based Process Visualization (SCADA/HMI/Dashboard) software developed by frangoteam, that allows unauthenticated remote attackers to modify arbitrary device tags via WebSockets. The vulnerability affects all FUXA deployments through version 1.2.9, including those with runtime.settings.secureEnabled set to true. It was published on February 4, 2026, and patched in version 1.2.10. It carries a CVSS v3.1 base score of 9.1 (Critical) and a CVSS v4.0 base score of 9.3 (Critical) (GitHub Advisory, FUXA Security Advisory).

Technical details

The root cause is CWE-862 (Missing Authorization): FUXA fails to perform authorization checks when actors attempt to access or modify device tags via its WebSocket interface, meaning even unauthenticated connections can issue privileged commands. This flaw bypasses role-based access controls entirely, including when security mode (secureEnabled) is active. An attacker can connect to the FUXA WebSocket endpoint without credentials and send crafted messages to overwrite arbitrary device tags or disable communication drivers. The fix in v1.2.10 addressed this by enforcing authentication and hardening validation for relevant request handling, including a fix for an authentication bypass related to heartbeat token refresh (FUXA Security Advisory, FUXA v1.2.10 Release).

Impact

Successful exploitation allows an unauthenticated remote attacker to overwrite arbitrary device tags or disable communication drivers in ICS/SCADA environments managed by FUXA, with high integrity and availability impact on both the vulnerable system and downstream industrial systems. Attackers could manipulate physical processes controlled by connected devices or disconnect devices from the HMI entirely, potentially causing operational disruption or unsafe physical conditions. Confidentiality impact is assessed as low, as the primary risk is unauthorized modification and disruption rather than data exfiltration (GitHub Advisory, FUXA Security Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (GitHub Advisory). The vulnerability requires no authentication, no user interaction, and no special preconditions, making it trivially exploitable by any network-accessible attacker. The EPSS score is approximately 0.021% (6th percentile), indicating a currently low but non-negligible probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability is not currently listed in the CISA KEV catalog.

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible FUXA instances running version 1.2.9 or earlier using tools such as Shodan or Censys, searching for the FUXA web interface (typically served on port 1881 by default).
  2. Establish WebSocket connection: Connect to the FUXA WebSocket endpoint (e.g., ws://<target>:<port>/) without providing any authentication credentials, as the server does not enforce authorization checks on this interface.
  3. Enumerate device tags: Send WebSocket messages to query or enumerate existing device tags and communication drivers configured in the FUXA instance to identify targets for manipulation.
  4. Overwrite device tags or disable drivers: Craft and send WebSocket messages that modify arbitrary device tag values or disable communication drivers, bypassing role-based access controls entirely — even if runtime.settings.secureEnabled is set to true.
  5. Achieve operational impact: The modified tags propagate to connected ICS/SCADA devices, potentially manipulating physical processes, causing equipment to behave unexpectedly, or disconnecting devices from the HMI (FUXA Security Advisory).

Indicators of compromise

  • Network: Unexpected or unauthenticated WebSocket connections to the FUXA server port (default 1881); WebSocket traffic containing device tag write or driver disable commands from unknown or external IP addresses.
  • Logs: FUXA application logs showing WebSocket sessions that perform tag modification or driver configuration changes without a preceding authenticated login event; anomalous sequences of tag write operations outside of normal operational hours.
  • Process/Application Behavior: Unexpected changes to device tag values in the FUXA HMI dashboard; communication drivers appearing disabled or offline without operator action; physical process deviations correlated with unauthorized tag writes.

Mitigation and workarounds

The primary remediation is to upgrade FUXA to version 1.2.10 or later, which fixes the authentication bypass related to heartbeat token refresh, enforces authentication on WebSocket and file upload endpoints, and hardens JWT secret handling (FUXA v1.2.10 Release, FUXA Security Advisory). As an interim workaround, restrict network access to FUXA systems at the firewall or network segmentation level to prevent unauthenticated external connections to the WebSocket interface. Monitor WebSocket connections for unauthorized access attempts while patching is in progress.

Community reactions

The vulnerability was reported by researcher wodzen and published by the FUXA maintainer unocelli on February 4, 2026, with a patch released simultaneously in v1.2.10. The advisory received attention on Mastodon via The Hacker Wire and was indexed by multiple vulnerability tracking platforms shortly after disclosure. No major vendor statements beyond the official GitHub advisory or significant media coverage have been identified.

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management