UXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An authorization bypass vulnerability in FUXA allows an unauthenticated, remote attacker to modify device tags via WebSockets. Exploitation allows an unauthenticated, remote attacker to bypass role-based access controls and overwrite arbitrary device tags or disable communication drivers, exposing connected ICS/SCADA environments to follow-on actions. This may allow an attacker to manipulate physical processes and disconnected devices from the HMI. This affects FUXA through version 1.2.9. This issue has been patched in FUXA version 1.2.10.
| Link | Resource |
|---|---|
| https://github.com/frangoteam/FUXA/releases/tag/v1.2.10 | Release Notes |
| https://github.com/frangoteam/FUXA/security/advisories/GHSA-ggxw-g3cp-mgf8 | Vendor Advisory |
10 Feb 2026, 14:31
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
| CPE | cpe:2.3:a:frangoteam:fuxa:*:*:*:*:*:*:*:* | |
| References | () https://github.com/frangoteam/FUXA/releases/tag/v1.2.10 - Release Notes | |
| References | () https://github.com/frangoteam/FUXA/security/advisories/GHSA-ggxw-g3cp-mgf8 - Vendor Advisory | |
| First Time |
Frangoteam fuxa
Frangoteam |
06 Feb 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2026-02-06 19:16
Updated : 2026-02-10 14:31
NVD link : CVE-2026-25752
Mitre link : CVE-2026-25752
CVE.ORG link : CVE-2026-25752
JSON object : View
Missing Authorization