FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' flag is commented out by default, causing the application to initialize with authentication disabled. This allows unauthenticated remote attackers to access sensitive API endpoints, modify projects, and control industrial equipment immediately after installation.
References
| Link | Resource |
|---|---|
| https://github.com/frangoteam/FUXA/blob/master/server/settings.default.js | Product |
Configurations
History
10 Feb 2026, 14:47
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Frangoteam
Frangoteam fuxa |
|
| CPE | cpe:2.3:a:frangoteam:fuxa:1.2.7:*:*:*:*:*:*:* | |
| References | () https://github.com/frangoteam/FUXA/blob/master/server/settings.default.js - Product |
09 Feb 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-1188 |
05 Feb 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.3 |
| CWE | CWE-79 |
03 Feb 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-03 18:16
Updated : 2026-02-10 14:47
NVD link : CVE-2025-69970
Mitre link : CVE-2025-69970
CVE.ORG link : CVE-2025-69970
JSON object : View
Products Affected
frangoteam
- fuxa
CWE
CWE-1188
Insecure Default Initialization of Resource
