CVE-2026-43945

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to achieve Full Remote Code Execution (RCE) as root. The exploit succeeds even when the platform is configured in its most secure state (Secure Mode Enabled and Node-RED Secure Auth Enabled). Version 1.3.1 fixes the issue.
CVSS

No CVSS.

Configurations

No configuration.

History

21 Jul 2026, 22:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-21 22:17

Updated : 2026-07-23 15:49


NVD link : CVE-2026-43945

Mitre link : CVE-2026-43945

CVE.ORG link : CVE-2026-43945


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-284

Improper Access Control

CWE-288

Authentication Bypass Using an Alternate Path or Channel

CWE-863

Incorrect Authorization