Junglewise Threat Intelligence

CVE-2026-25751: FUXA unauthenticated exposure of plaintext database credentials

CVE-2026-25751 · Severity: medium · CVSS 4 · Published 2026-02-05

Technologies: FUXA Project FUXA, fuxa-server (npm). Vendors: npm.

Executive brief

FUXA is an industrial automation and SCADA visualization platform used to monitor and control manufacturing and process systems. An unauthenticated attacker can remotely retrieve plaintext database credentials and full system configuration, bypassing all security settings. With these credentials, an attacker can directly access the connected InfluxDB database to steal historical data, corrupt records, or cause service outages.

Technical details

FUXA suffers from an information disclosure vulnerability (CWE-306, CWE-312) that exposes plaintext administrative credentials in its configuration without requiring authentication. The vulnerability affects all versions through 1.2.9 and can be exploited remotely over the network with no preconditions or privileges required. An attacker can obtain the complete system configuration including InfluxDB database credentials, which enables direct database access to read, modify, delete historical data, or perform denial-of-service attacks. A patch is available in version 1.2.10.

Affected products

  • FUXA Project FUXA <= 1.2.9

Timeline

  • 2026-02-05: disclosed
  • 2026-02-05: patched: Fixed in version 1.2.10

References

Related threats