frangoteam FUXA是frangoteam组织开源的一款工业控制软件。 frangoteam FUXA 1.3.2之前版本存在授权问题漏洞,该漏洞源于对调度程序设置权限验证不当,可能导致经过身份验证的非管理员操作员创建或修改设备操作、删除计划,进而获得设备值更改和服务器端项目脚本执行权限。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| frangoteam | FUXA | < 1.3.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| frangoteam | FUXA | < 1.3.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-67443 | 9.2 CRITICAL | FUXA: Unauthenticated guest JWT bypasses Node-RED secure-mode authorization gate (Remote S |
| CVE-2026-47719 | 8.2 HIGH | FUXA: Unauthenticated SSRF via Socket.IO DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY with re |
| CVE-2026-65984 | 7.5 HIGH | FUXA: JWT lifecycle flaws allow deleted or demoted users to retain privileged sessions |
| CVE-2026-67440 | 6.9 MEDIUM | FUXA: Unauthenticated Socket.IO read events |
| CVE-2026-65985 | 6.0 MEDIUM | FUXA: SSRF hardening for `device-webapi-request` |
| CVE-2026-47720 | 5.3 MEDIUM | FUXA: SQL injection in TDengine DAQ connector via backslash bypass of escapeTdString |
| CVE-2026-67442 | 2.0 LOW | FUXA Business Logic Flaw: Role Deletion Without User Assignment Cleanup |
No comments yet