FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This affects FUXA through version 1.2.9. This issue has been patched in FUXA version 1.2.10.
References
Configurations
History
13 Feb 2026, 20:32
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:frangoteam:fuxa:*:*:*:*:*:*:*:* | |
| First Time |
Frangoteam
Frangoteam fuxa |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| References | () https://github.com/frangoteam/FUXA/commit/22c2192f5d9beef8a787c45eff3a14c24dbb5f96 - Patch | |
| References | () https://github.com/frangoteam/FUXA/releases/tag/v1.2.10 - Release Notes | |
| References | () https://github.com/frangoteam/FUXA/security/advisories/GHSA-88qh-cphv-996c - Vendor Advisory |
09 Feb 2026, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-09 23:16
Updated : 2026-02-13 20:32
NVD link : CVE-2026-25895
Mitre link : CVE-2026-25895
CVE.ORG link : CVE-2026-25895
JSON object : View
Products Affected
frangoteam
- fuxa
