Vulnerability Description
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to achieve Full Remote Code Execution (RCE) as root. The exploit succeeds even when the platform is configured in its most secure state (Secure Mode Enabled and Node-RED Secure Auth Enabled). Version 1.3.1 fixes the issue.
Related Weaknesses (CWE)
References
- https://github.com/frangoteam/FUXA/releases/tag/v1.3.1
- https://github.com/frangoteam/FUXA/security/advisories/GHSA-p69w-mmfv-xrfj
FAQ
What is CVE-2026-43945?
CVE-2026-43945 is a documented vulnerability. FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to achieve Full Remote Code Execution (RCE) as root. The ...
How severe is CVE-2026-43945?
CVSS scoring is not yet available for CVE-2026-43945. Check NVD for updates.
Is there a patch for CVE-2026-43945?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.