CVE-2026-25895 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 6.2% (pctl 93)
Patch early
A public exploit exists.
Description
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This affects FUXA through version 1.2.9. This issue has been patched in FUXA version 1.2.10.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 6.21% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2026-02-09 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| frangoteam | fuxa |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | FUXA 1.2.9 - RCE | 2026-05-21 |
References
→ the Explorer · watch your stack · NVD