Back to overview

CVE-2026-43945

HIGH
8.9
CVSS 4.0
Description
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to achieve Full Remote Code Execution (RCE) as root. The exploit succeeds even when the platform is configured in its most secure state (Secure Mode Enabled and Node-RED Secure Auth Enabled). Version 1.3.1 fixes the issue.

Metadata

CVE ID
CVE-2026-43945
State
PUBLISHED
Assigner
GitHub_M
Reserved
2026-05-04 16:59 UTC
Published
2026-07-21 21:24 UTC
Last updated
2026-07-21 21:24 UTC
Primary CWE
CWE-94
CWE-94: Improper Control of Generation of Code ('Code Inject…
Vendor / Product
frangoteam / FUXA
Sources
cve.org  ·  NVD

Severity & Metrics

8.9 HIGH CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Affected products (1)
VendorProductPlatformVersions
frangoteam FUXA >= 1.2.11, < 1.3.1
Weakness (CWE)
CWESourceDescription
CWE-284 cna CWE-284: Improper Access Control
CWE-288 cna CWE-288: Authentication Bypass Using an Alternate Path or Channel
CWE-863 cna CWE-863: Incorrect Authorization
CWE-94 cna CWE-94: Improper Control of Generation of Code ('Code Injection')
CVSS scores (1)
ScoreSeverityVersionSourceVector
8.9 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
References (2)
Back to overview