peter bassill · operator
$ cve CVE-2026-25895 JSON

CVE-2026-25895 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 6.2% (pctl 93)

Patch early

A public exploit exists.

Description

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This affects FUXA through version 1.2.9. This issue has been patched in FUXA version 1.2.10.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.21% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2026-02-09
Last modified2026-06-17

Affected (1)

VendorProduct
frangoteamfuxa

Public exploits

SourceTitleDate
exploit-dbFUXA 1.2.9 - RCE2026-05-21

References

→ the Explorer  ·  watch your stack  ·  NVD