216.73.216.6

CVE-2026-25939

· Published 09/02/2026 23:16 · Modified 10/02/2026 15:22

Labels: CVE-2026-25939 2026-02-09CVE-2026-25939CWE-862[email protected]

Essential information

Published
09/02/2026 23:16
Modified
10/02/2026 15:22
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authorization bypass vulnerability in the FUXA allows an unauthenticated, remote attacker to create and modify arbitrary schedulers, exposing connected ICS/SCADA environments to follow-on actions. This has been patched in FUXA version 1.2.11.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
fuxa / fuxa cpe:2.3:a:fuxa:fuxa:1.2.8-1.2.10:*:*:*:*:*:*:*
fuxa / fuxa cpe:2.3:a:fuxa:fuxa:1.2.11:*:*:*:*:*:*:*

References