CVE-2026-47720Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengine DAQ storage connector's escapeTdString function in server/runtime/storage/tdengine/index.js doubles single quotes but does not escape backslashes. A remote unauthenticated attacker can submit a crafted sids tag identifier through GET /api/daq or the Socket.IO DAQ_QUERY event so TDengine interprets the backslash and quote sequence as SQL syntax. The injected query can return every row from fuxa.meters, exposing historical PLC tag values, device identifiers, and device names even when FUXA authentication is enabled. This issue is fixed in version 1.3.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-18: 2Patch / Workaround · 2026-08-18: 1Technical Details · 2026-08-18: 208-18
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-47720 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengine DAQ storage connector's escapeTdString function in server/runti… https://www.cve.org/CVERecord?id=CVE-2026-47720 ----- Traducción: CVE-2026-47720 FUX… https://infoflow.cloud`

    Post summary

    The tweet references CVE-2026-47720, links to its record, and mentions the affected escapeTdString function, but provides no PoC, exploit code, patch, or active exploitation evidence.

    0000030
    100 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-47720 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengine DAQ storage connector's escapeTdString function in server/runti… https://www.cve.org/CVERecord?id=CVE-2026-47720

    Post summary

    The post announces CVE-2026-47720 affecting FUXA’s TDengine DAQ connector before v1.3.2 and notes that an update (v1.3.2) addresses the flaw, but it does not provide PoC, exploit details, or evidence of active exploitation.

    00000925
    58.0K followersView on X

Explore more