CVE 9.5 CRITICAL

FUXA Unauthenticated Remote Code Execution via Hardcoded JWT Secret in Default Configuration_CVE-2026-25894

9.5 / 10
CRITICAL
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Description

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An insecure default configuration in FUXA allows an unauthenticated, remote attacker to gain administrative access and execute arbitrary code on the server. This affects FUXA through version 1.2.9 when authentication is enabled, but the administrator JWT secret is not configured. This issue has been patched in FUXA version 1.2.10.

AI Analysis

Unauthenticated remote code execution via hardcoded JWT secret in default configuration

Basic Information

ID CVE-2026-25894
Source GitHub_M
Published Feb 9, 2026 at 22:28

Affected Product

Vendor frangoteam
Product FUXA
Version < 1.2.10
Affected Versions frangoteam FUXA < 1.2.10

CWE Classification

AI Assessment

AI Score 9.5 / 10
AI Severity Critical
Vendor frangoteam
Product FUXA
Version < 1.2.10

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.