Executive brief
FUXA is an industrial control and SCADA visualization platform used to monitor and control connected devices and infrastructure. An unauthenticated attacker can bypass authorization checks to create, modify, or delete schedules that automatically execute actions on connected industrial equipment—potentially forcing devices into unsafe states or executing malicious commands without any authentication requirement.
Technical details
This is an authorization bypass vulnerability (CWE-862) in FUXA's scheduler endpoint that allows unauthenticated, remote attackers to automatically authenticate as guest and manipulate scheduling rules. The attack requires no network authentication, credentials, or user interaction—only network reachability to the FUXA service. An attacker can create or modify schedules to trigger immediately or cyclically, forcing connected ICS/SCADA devices to specific states or executing existing scripts on the server. This affects versions 1.2.8 through 1.2.10; the vulnerability has been patched in version 1.2.11.
Affected products
- Frangoteam FUXA 1.2.8 through 1.2.10
Timeline
- 2026-02-09: disclosed: Advisory published on GitHub
- 2026-02-10: patched: Fixed in version 1.2.11