CVE-2026-25951Disclosure(frangoteam / fuxa)

LOWCVSS 7.2 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.11, there is a flaw in the path sanitization logic allows an authenticated attacker with administrative privileges to bypass directory traversal protections. By using nested traversal sequences (e.g., ....//), an attacker can write arbitrary files to the server filesystem, including sensitive directories like runtime/scripts. This leads to Remote Code Execution (RCE) when the server reloads the malicious scripts. This vulnerability is fixed in 1.2.11.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-23CWE-184

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fuxa

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-10); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
fuxa

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-09: 1Mentions · 2026-02-10: 2Mentions · 2026-02-11: 1PoC Mentioned / Linked · 2026-02-11: 1Technical Details · 2026-02-09: 1Technical Details · 2026-02-10: 2Technical Details · 2026-02-11: 102-0902-1002-11
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-091
Disclosure1
2026-02-102
Disclosure2
2026-02-111
Disclosure1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-25951 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.11, there is a flaw in the path sanitization logic allows an authenticated atta… https://www.cve.org/CVERecord?id=CVE-2026-25951

    Post summary

    A flaw in the path sanitization logic in FUXA before version 1.2.11 permits authenticated attackers to potentially exploit the vulnerability, and a CVE record has been published.

    01020253
    56.5K followersView on X
  • Mohamed Aziz Hidri@0xh1dr1
    Disclosure

    I am happy to share that I have helped secure FUXA SCADA, one of the most widely deployed HMI/SCADA systems. I’m starting the year strong with CVE-2026-25951, a high severity bug with a CVSS score of 9.0. https://github.com/frangoteam/FUXA/security/advisories/GHSA-68m5-5w2h-h837 https://t.co/wYgLz4pl9Q

    Post summary

    The author announces the discovery of CVE-2026-25951, a high‑severity vulnerability in FUXA SCADA with a CVSS score of 9.0, and provides a link to a GitHub security advisory that likely contains further technical details.

    0001059
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25951 Authenticated Path Traversal in FUXA SCADA Software Enables Remote Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25951

    Post summary

    The text announces CVE-2026-25951, describing an authenticated path traversal flaw in FUXA SCADA software that allows remote code execution.

    0001091
    4.0K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25951: FUXA Faux Pas: From Weak Regex to SCADA RCE A critical path traversal vulnerability in the FUXA SCADA/HMI web interface allows authenticated administrators to escape the filesystem sandbox using nested directory sequences. Because FUXA... https://cvereports.com/reports/CVE-2026-25951

    Post summary

    The report describes a critical path traversal flaw in the FUXA SCADA/HMI web interface that permits authenticated admins to escape the filesystem sandbox via nested directory sequences, potentially enabling remote code execution.

    0000055
    27 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfrangoteamfuxa---

Explore more