CVE-2026-43945 HIGH

CVE-2026-43945: FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection

Vendor Frangoteam
Product FUXA
Weakness CWE-94 · Code injection
Published July 21, 2026
Last update July 21, 2026

CVSS base score

8.9/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to achieve Full Remote Code Execution (RCE) as root. The exploit succeeds even when the platform is configured in its most secure state (Secure Mode Enabled and Node-RED Secure Auth Enabled). Version 1.3.1 fixes the issue.

Key dates

02Disclosure timeline

July 21, 2026 CVE published

Related vulnerabilities

04Related CVE