CVE-2026-43945 Details
Description
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to achieve Full Remote Code Execution (RCE) as root. The exploit succeeds even when the platform is configured in its most secure state (Secure Mode Enabled and Node-RED Secure Auth Enabled). Version 1.3.1 fixes the issue.
A full remote code execution vulnerability has been identified in FUXA versions 1.2.11 prior to 1.3.1. This vulnerability allows an unauthenticated remote attacker to execute code as root, even when the platform is in its most secure configuration, with Secure Mode and Node-RED Secure Auth enabled. The issue arises from a path manipulation flaw in the authentication middleware, which can be exploited to bypass security checks on administrative Node-RED endpoints, potentially leading to remote code execution within the container context.
Users can update to FUXA version 1.3.1 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 21, 2026CISA-ADP
Assessed Jul 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/frangoteam/FUXA/releases/tag/v1.3.1 | [email protected] | Release NotesVendor |
| https://github.com/frangoteam/FUXA/security/advisories/GHSA-p69w-mmfv-xrfj | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
| CWE-288 | Authentication Bypass Using an Alternate Path or Channel | [email protected] |
| CWE-863 | Incorrect Authorization | [email protected] |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| FUXA | >= 1.2.11, <= 1.3.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Modified | CISA-ADP |
| Jul 21, 2026 | New CVE Received | [email protected] |
Volerion