CCB Alert@CCBalertPatch
Multiple critical CVEs in FUXA SCADA with CVSS scores ranging from 10.0 to 9.3; updating to version 1.2.11 or later is advised to mitigate potential full system compromise.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
CVE-2026-25938 is an authentication bypass vulnerability in FUXA 1.2.8‑1.2.10 that allows remote code execution; no PoC, exploit, patch, or active exploitation details are provided.
CVE@CVEnewDisclosure
A new authentication bypass vulnerability (CVE‑2026‑25938) in FUXA’s web‑based process visualization software is disclosed, impacting versions 1.2.8 through 1.2.10.
UNDERCODE TESTING@UndercodeUpdatePoC
The post presents a proof‑of‑concept for CVE‑2026‑25938, detailing an authentication bypass that yields unauthenticated RCE on Node‑RED, while also offering mitigation steps and a walkthrough video.
PulsePatch.io@pulsepatchioPatch
The post alerts users of CVE-2026-25938, an unauthenticated RCE in FUXA Server's Node-RED integration, and advises upgrading to version 1.2.11 or later to mitigate the flaw.
cvereports@_cvereportsDisclosure
CVE-2026-25938 exposes an authentication bypass in FUXA’s Node‑RED integration, allowing remote code execution by failing to validate JWT tokens on proxied routes.