CVE-2023-33831

CRITICAL EXPLOITED NUCLEI

FUXA 1.1.13 - RCE

Title source: llm

Description

A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request.

Exploits (2)

nomisec WORKING POC 10 stars
by rodolfomarianocy · remote
https://github.com/rodolfomarianocy/Unauthenticated-RCE-FUXA-CVE-2023-33831
nomisec WORKING POC
by btar1gan · remote
https://github.com/btar1gan/exploit_CVE-2023-33831

Nuclei Templates (1)

FUXA - Unauthenticated Remote Code Execution
CRITICALVERIFIEDby gy741
FOFA: title="FUXA" || title="fuxa"

Scores

CVSS v3 9.8
EPSS 0.9335
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2023-11-16
CWE
CWE-77
Status published
Products (2)
frangoteam/fuxa 1.1.13
frangoteam/fuxa 0npm
Published Sep 18, 2023
Tracked Since Feb 18, 2026