CVE-2023-33831

CRITICAL EXPLOITED NUCLEI

FUXA 1.1.13 - Remote Code Execution via /api/runscript Endpoint

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2023-33831 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including rodolfomarianocy, btar1gan. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit targets an unauthenticated RCE vulnerability in FUXA V.1.1.13-1186 via the /api/runscript endpoint. It leverages Node.js's child_process.exec to spawn a reverse shell by injecting a malicious script into the 'code' parameter.

Description

A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request.

Exploits (2)

nomisec WORKING POC 10 stars
by rodolfomarianocy · remote
https://github.com/rodolfomarianocy/Unauthenticated-RCE-FUXA-CVE-2023-33831

This exploit targets an unauthenticated RCE vulnerability in FUXA V.1.1.13-1186 via the /api/runscript endpoint. It leverages Node.js's child_process.exec to spawn a reverse shell by injecting a malicious script into the 'code' parameter.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: FUXA V.1.1.13-1186
No auth needed
Prerequisites: Network access to the target's /api/runscript endpoint · Target must be running FUXA V.1.1.13-1186
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by btar1gan · remote
https://github.com/btar1gan/exploit_CVE-2023-33831

This exploit leverages CVE-2023-33831 to achieve remote code execution (RCE) by sending a crafted JSON payload to a vulnerable API endpoint, triggering a reverse shell via Node.js `child_process.exec`.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Unknown (likely a Node.js-based application with an API endpoint vulnerable to command injection)
No auth needed
Prerequisites: Network access to the target API endpoint · Listener set up to receive the reverse shell
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

FUXA - Unauthenticated Remote Code Execution
CRITICALVERIFIEDby gy741
FOFA: title="FUXA" || title="fuxa"

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.9335
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2023-11-16
CWE
CWE-77
Status published
Products (2)
frangoteam/fuxa 1.1.13
frangoteam/fuxa 0npm
Published Sep 18, 2023
Tracked Since Feb 18, 2026