CVE-2026-25895Disclosure(frangoteam / fuxa)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch frangoteam fuxa systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This affects FUXA through version 1.2.9. This issue has been patched in FUXA version 1.2.10.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-306

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fuxa

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 3 mentions (2026-02-10); latest day: 2
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
fuxa

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-02-09: 1Mentions · 2026-02-10: 3Mentions · 2026-05-21: 1Mentions · 2026-08-19: 2Active Exploitation · 2026-08-19: 1Patch / Workaround · 2026-02-10: 2Technical Details · 2026-02-09: 1Technical Details · 2026-02-10: 3Technical Details · 2026-05-21: 1Technical Details · 2026-08-19: 202-0902-1005-2108-19
Signal classification3 categories
Disclosure
457.1%
Patch
228.6%
Active Exploitation
114.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-091
Disclosure1
2026-02-103
Disclosure1Patch2
2026-05-211
Disclosure1
2026-08-192
Active Exploitation1Disclosure1
Full discourse7 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-25895 - critical 🚨 FUXA <= 1.2.9 - Unauthenticated Path Traversal to Arbitrary File Write > FUXA, an open-source Node.js SCADA/HMI web interface, through version 1.2.9 exposes a... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-25895 @pdnuclei #NucleiTempl...

    Post summary

    The CVE-2026-25895 vulnerability affects FUXA versions up to 1.2.9, enabling unauthenticated path traversal for arbitrary file writes, with details provided via a ProjectDiscovery reference.

    01092420
    1.3K followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    FUXA 1.2.9 industrial HMI platform suffers from unauthenticated path traversal leading to arbitrary file write and RCE. Zero-click exploitation bypasses all authentication mechanisms including secure mode. Key technical details: • CVE-2026-25895: POST /api/upload endpoint lacks authentication middleware entirely • Path traversal via `destination` parameter: `a/../../../../<target>` escapes appDir containment • Node.js path.resolve() vulnerability enables write to any filesystem location • Multiple RCE vectors: settings.js replacement, cron injection, SSH key drops, webshell deployment Attack methodology: • Unauthenticated /api/settings leak reveals installation paths and running user context • Exploitation works even with secureEnabled=true (JWT bypass) • Settings.js replacement executes on next FUXA restart via require() mechanism • Cron payloads provide immediate execution when FUXA runs as root (common in containers) DFIR artifacts and detection opportunities: • Monitor POST requests to /api/upload with directory traversal patterns in JSON body • Watch for unexpected files in /tmp/, /etc/cron.d/, and FUXA _appdata directories • Alert on settings.js modifications and unauthorized SSH key additions • Network detection: outbound connections from industrial systems to unexpected ports Hunt for recent file modifications in FUXA directories, especially settings.js timestamps mismatched with legitimate configuration changes. #DFIR_Radar

    Post summary

    The text announces a new vulnerability (CVE‑2026‑25895) in FUXA 1.2.9, detailing the lack of authentication on /api/upload, path‑traversal via the destination parameter, and multiple RCE vectors, but it does not provide a PoC, tool, active exploitation claim, or patch information.

    10110800
    1.5K followersView on X
  • CyberTLDR@CyberTLDR
    Active Exploitation

    1/3 Attackers are actively hitting two critical open source flaws right now. An unauthenticated MLflow SSRF (CVE-2026-64849, CVSS 9.3) steals cloud creds and a FUXA bug (CVE-2026-25895, CVSS 9.5) gives full RCE. Patched? #CyberSecurity #InfoSec #RTXPowersPlay

    Post summary

    The tweet reports that two critical open‑source vulnerabilities (CVE‑2026‑64849 and CVE‑2026‑25895) are being actively exploited, but it does not mention any patch or exploit code.

    1000050
    40 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: multiple critical in #FUXA #SCADA #ICS CVE-2026-25939, CVE-2026-25893, CVE-2026-25894, CVE-2026-25895 &amp; CVE-2026-25938 CVSS: 10.0-9.3 Network based attackers can cause full system compromise. Update to 1.2.11 or later https://github.com/frangoteam/FUXA/releases/tag/v1.2.11 #Patch #Patch #Patch

    Post summary

    The message is a patch advisory warning users of multiple critical CVEs in FUXA SCADA/ICS and urges updating to version 1.2.11 or later.

    01000209
    7.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25895 Unauthenticated Path Traversal in FUXA Web-Based SCADA Software https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25895

    Post summary

    The entry references CVE-2026-25895 as an unauthenticated path traversal issue in FUXA Web-Based SCADA Software, but offers no further details on PoC, exploitation, or remediation.

    0001073
    4.0K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: CVE-2026-25895 in frangoteam FUXA (&lt;1.2.10) lets unauthenticated attackers write files anywhere on the server. SCADA/HMI systems at high risk — patch now! 🔒 https://radar.offseq.com/threat/cve-2026-25895-cwe-22-improper-limitation-of-a-pat-61293111 #OffSeq #SCADA #... https://t.co/pCVuT5Z52P

    Post summary

    The tweet highlights CVE‑2026‑25895 in frangoteam FUXA (<1.2.10), which allows unauthenticated file write, and urges immediate patching to mitigate the high risk to SCADA/HMI systems.

    0000049
    268 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25895 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write a… https://www.cve.org/CVERecord?id=CVE-2026-25895

    Post summary

    A path traversal vulnerability in FUXA permits unauthenticated remote attackers to write files, but no evidence of exploitation or mitigations is presented.

    00000222
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfrangoteamfuxa---

Explore more