CVE-2026-25895
CRITICALFrangoteam Fuxa < 1.2.10 - Path Traversal
Title source: ruleDescription
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This affects FUXA through version 1.2.9. This issue has been patched in FUXA version 1.2.10.
Scores
CVSS v3
9.8
EPSS
0.0005
EPSS Percentile
14.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-22
CWE-306
Status
published
Affected Products (2)
frangoteam/fuxa
< 1.2.10
npm/fuxa-server
< 1.2.10npm
Timeline
Published
Feb 09, 2026
Tracked Since
Feb 18, 2026