# CVE-2026-25938

## Summary

- **CVE ID:** CVE-2026-25938
- **Severity:** CRITICAL
- **CVSS Score:** 9.5 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
- **CWE:** CWE-290, CWE-306
- **Published:** Feb 9, 2026
- **Last Modified:** Mar 12, 2026

## Description

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to execute arbitrary code on the server when the Node-RED plugin is enabled. This has been patched in FUXA version 1.2.11.

## Affected Products

- frangoteam — FUXA (>= 1.2.8, < 1.2.11)

## References

- [CNA](https://github.com/frangoteam/FUXA/security/advisories/GHSA-v4p5-w6r3-2x4f)
- [CNA](https://github.com/frangoteam/FUXA/commit/5e7679b09718534e4501a146fdfe093da29af336)
- [CNA](https://github.com/frangoteam/FUXA/releases/tag/v1.2.11)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.98%
- **EPSS Percentile:** 60.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._