Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Frangoteam

First CVE: Mar 16, 2022Active for: 4 yearsTotal CVEs: 19
73.7
VTI Score
TOP TARGET

Frangoteam develops FUXA, a web-based industrial automation and SCADA platform that has exhibited a pattern of critical-severity vulnerabilities concentrated in authentication, file-inclusion, and injection weaknesses typical of server-side PHP applications exposed to untrusted input. The vendor's disclosures span missing authentication on critical functions, remote file inclusion, path traversal, SQL injection, and insecure default configurations—a cluster that reflects both the difficulty of hardening web-facing industrial software and the appeal of such platforms to adversaries seeking access to operational infrastructure. Vulnerabilities affecting this vendor frequently acquire public exploit tooling, and the scope and severity of the recurring weakness classes warrant close attention from defenders managing or monitoring FUXA deployments. Current severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
19
Total CVEs
More Total CVEs than 96% of tracked vendors
6.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
9.0
Avg CVSS Score
Higher Avg CVSS Score than 87% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Frangoteam over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 16, 2022
4 years ago
Most Recent CVE
Feb 24, 2026
151 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-69985CRITICAL
FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, wh
Feb 24, 20269.848NOYES
CVE-2023-33831CRITICAL
A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request.
Sep 18, 20239.846NOYES
CVE-2026-25895CRITICAL
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files
Feb 9, 20269.845NOYES
CVE-2023-31719CRITICAL
FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin.
Sep 22, 20239.841NONO
CVE-2025-69971CRITICAL
FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-coded secret key to sign and verify JWT Tokens. This allows remo
Feb 3, 20269.839NOYES
CVE-2026-25939CRITICAL
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authorization bypass vulnerability in the FUXA allows an unauthenti
Feb 9, 20269.136NONO
CVE-2026-25938CRITICAL
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remot
Feb 9, 20269.832NONO
CVE-2026-25894CRITICAL
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An insecure default configuration in FUXA allows an unauthenticated, remote attacker to gain administrativ
Feb 9, 20269.832NONO
CVE-2026-25893CRITICAL
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker
Feb 9, 20269.831NONO
CVE-2026-25752CRITICAL
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An authorization bypass vulnerability in FUXA allows an unauthenticated, remote attacker to modify device
Feb 6, 20269.129NONO
View all 19 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products19 CVEs
32%
68%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network19 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None18 (94.7%)
Unknown0 (0.0%)
Required1 (5.3%)
Privileges Required
Low0 (0.0%)
High1 (5.3%)
None18 (94.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
10.5% of CVEs· 96th percentile
ExploitDB
2 CVEs
10.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Frangoteam.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Frangoteam — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Frangoteam's Products

View all 2 CNAs →

Top CWEs