Executive brief
FUXA is a web-based SCADA/HMI dashboard software used to visualize and control industrial processes. The vulnerability allows unauthenticated attackers to bypass authentication by spoofing the HTTP Referer header, gaining access to run arbitrary Node.js code on the server. This leads to complete system compromise and can allow attackers to execute commands, modify data, or disrupt critical operations.
Technical details
The vulnerability is a failure of authentication verification in the JWT middleware located at server/api/jwt-helper.js. The middleware implements an insufficient check that relies on the presence of "/fuxa" in the HTTP Referer header to validate that requests are coming from internal sources, bypassing the normal JWT token requirement. An unauthenticated remote attacker can craft HTTP POST requests to the /api/runscript endpoint with a spoofed Referer header containing "/fuxa" to pass authentication checks. No prerequisites are required (no valid JWT, no login credentials needed). Successful exploitation allows execution of arbitrary Node.js code on the server via the runscript functionality, leading to remote code execution. This is an incomplete fix for an earlier CVE-2023-33831; the current whitelist check is insufficient. Patches should be available in versions after 1.2.8.
Affected products
- frangoteam FUXA 1.2.8 and prior
Timeline
- 2026-02-24: disclosed: Vulnerability published on GitHub Advisory Database (GHSA-4r4r-4jp4-wwf9)
- 2025-12-19: other: Proof-of-concept exploit code published demonstrating RCE and admin account takeover