CVE-2026-25752 describes an authorization bypass vulnerability in FUXA (versions through 1.2.9), a web-based SCADA/HMI software. This flaw allows an unauthenticated, remote attacker to manipulate device tags via WebSockets, bypassing role-based access controls. The vulnerability carries a critical CVSS score of 9.1, indicating high impact on integrity and availability, as it can lead to the manipulation of physical processes or the disabling of communication drivers in connected ICS/SCADA environments. There is currently no public exploit code (Metasploit, Nuclei, ExploitDB), and it is not known to be actively exploited, with minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.10CPE matchmatch criteria | cpe:2.3:a:frangoteam:fuxa:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.