CVE-2025-69970

F

UXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' flag is commented out by default, causing the application to initialize with authentication disabled. This allows unauthenticated remote attackers to access sensitive API endpoints, modify projects, and control industrial equipment immediately after installation.

Configurations

Configuration 1 (hide)

cpe:2.3:a:frangoteam:fuxa:1.2.7:*:*:*:*:*:*:*

History

10 Feb 2026, 14:47

Type Values Removed Values Added
First Time Frangoteam fuxa
Frangoteam
References () https://github.com/frangoteam/FUXA/blob/master/server/settings.default.js - () https://github.com/frangoteam/FUXA/blob/master/server/settings.default.js - Product
CPE cpe:2.3:a:frangoteam:fuxa:1.2.7:*:*:*:*:*:*:*

09 Feb 2026, 22:16

Type Values Removed Values Added
CWE CWE-79 CWE-1188

05 Feb 2026, 15:16

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.3

03 Feb 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-03 18:16

Updated : 2026-02-10 14:47


NVD link : CVE-2025-69970

Mitre link : CVE-2025-69970

CVE.ORG link : CVE-2025-69970


JSON object : View

Products Affected
CWE
CWE-1188

Initialization of a Resource with an Insecure Default