Frangoteam develops FUXA, a web-based industrial automation and SCADA platform that has exhibited a pattern of critical-severity vulnerabilities concentrated in authentication, file-inclusion, and injection weaknesses typical of server-side PHP applications exposed to untrusted input. The vendor's disclosures span missing authentication on critical functions, remote file inclusion, path traversal, SQL injection, and insecure default configurations—a cluster that reflects both the difficulty of hardening web-facing industrial software and the appeal of such platforms to adversaries seeking access to operational infrastructure. Vulnerabilities affecting this vendor frequently acquire public exploit tooling, and the scope and severity of the recurring weakness classes warrant close attention from defenders managing or monitoring FUXA deployments. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Frangoteam over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-69985CRITICAL FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, wh | Feb 24, 2026 | 9.8 | 48 | NO | YES |
CVE-2023-33831CRITICAL A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request. | Sep 18, 2023 | 9.8 | 46 | NO | YES |
CVE-2026-25895CRITICAL FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files | Feb 9, 2026 | 9.8 | 45 | NO | YES |
CVE-2023-31719CRITICAL FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin. | Sep 22, 2023 | 9.8 | 41 | NO | NO |
CVE-2025-69971CRITICAL FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-coded secret key to sign and verify JWT Tokens. This allows remo | Feb 3, 2026 | 9.8 | 39 | NO | YES |
CVE-2026-25939CRITICAL FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10,
an authorization bypass vulnerability in the FUXA allows an unauthenti | Feb 9, 2026 | 9.1 | 36 | NO | NO |
CVE-2026-25938CRITICAL FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remot | Feb 9, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-25894CRITICAL FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An insecure default configuration in FUXA allows an unauthenticated, remote attacker to gain administrativ | Feb 9, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-25893CRITICAL FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker | Feb 9, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-25752CRITICAL FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An authorization bypass vulnerability in FUXA allows an unauthenticated, remote attacker to modify device | Feb 6, 2026 | 9.1 | 29 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Frangoteam.
Media articles that mention a CVE ID that affects a product developed by Frangoteam — matched by CVE ID, not by vendor name.