Junglewise Threat Intelligence

CVE-2025-69985: FUXA authentication bypass in JWT middleware via Referer header spoofing

CVE-2025-69985 · Severity: low · CVSS 3.1 · Published 2026-02-24

Technologies: Frangoteam FUXA, @frangoteam/fuxa (npm). Vendors: Frangoteam, npm.

Executive brief

FUXA is a web-based SCADA/HMI dashboard software used to visualize and control industrial processes. The vulnerability allows unauthenticated attackers to bypass authentication by spoofing the HTTP Referer header, gaining access to run arbitrary Node.js code on the server. This leads to complete system compromise and can allow attackers to execute commands, modify data, or disrupt critical operations.

Technical details

The vulnerability is a failure of authentication verification in the JWT middleware located at server/api/jwt-helper.js. The middleware implements an insufficient check that relies on the presence of "/fuxa" in the HTTP Referer header to validate that requests are coming from internal sources, bypassing the normal JWT token requirement. An unauthenticated remote attacker can craft HTTP POST requests to the /api/runscript endpoint with a spoofed Referer header containing "/fuxa" to pass authentication checks. No prerequisites are required (no valid JWT, no login credentials needed). Successful exploitation allows execution of arbitrary Node.js code on the server via the runscript functionality, leading to remote code execution. This is an incomplete fix for an earlier CVE-2023-33831; the current whitelist check is insufficient. Patches should be available in versions after 1.2.8.

Affected products

  • frangoteam FUXA 1.2.8 and prior

Timeline

  • 2026-02-24: disclosed: Vulnerability published on GitHub Advisory Database (GHSA-4r4r-4jp4-wwf9)
  • 2025-12-19: other: Proof-of-concept exploit code published demonstrating RCE and admin account takeover

References

Related threats