← Späť na vyhľadávanie CVE

CVE-2026-43945

FUXA

Popis

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to achieve Full Remote Code Execution (RCE) as root. The exploit succeeds even when the platform is configured in its most secure state (Secure Mode Enabled and Node-RED Secure Auth Enabled). Version 1.3.1 fixes the issue.

CVSS 8.9EPSS 0.8619999999999999%Riziko 0.96
Zobraziť zdroj
Zverejnené
2026-07-21 22:17:01
Dotknuté verzie
<=1.3.1
Typ
Webová aplikácia
Posledná úprava
2026-07-23 15:49:31
Vektor
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X