Record summary

CVE-2026-47717 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. Version 1.3.1 fixes the issue.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 13, 2026 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List= 1.3.0affected
GitHub Advisory1.3.0affected
1.3.0 to < 1.3.1 · Fixed in 1.3.1affected

Nuclei templates

1
ProjectDiscoveryHIGHFUXA 1.3.0 - Unauthenticated ICS/SCADA Project Data DisclosureCVSS 7.5

FUXA v1.3.0 exposes full SCADA/HMI project configuration via GET /api/project without authentication, even when secureEnabled is true. The secureFnc middleware auto-generates a valid guest JWT when no token is provided, bypassing authentication. Exposed data includes server-side scripts, device configs, HMI views, and alarm definitions.

Remediation

Upgrade to fuxa-server version 1.3.1 or later.

WeaknessesCWE-201
Authorspussycat0x
Template tagscvecve2026fuxaicsscadaunauthexposure
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Shodan: http.title:"FUXA"
FOFA: title="FUXA"

Source: ProjectDiscovery

References

3