CVE-2025-69985 is a critical authentication bypass vulnerability in FUXA versions 1.2.8 and prior, allowing unauthenticated remote attackers to achieve Remote Code Execution (RCE). The flaw stems from improper validation of the HTTP "Referer" header in the server/api/jwt-helper.js middleware. By spoofing the Referer header, attackers can bypass JWT authentication and access the /api/runscript endpoint to execute arbitrary Node.js code. This vulnerability carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.2.8CPE matchmatch criteria | cpe:2.3:a:frangoteam:fuxa:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.