Executive brief
FUXA, an open-source industrial web-based SCADA system, contains a security flaw in how it communicates with TDengine databases. An attacker can exploit this to bypass security filters and read historical data from connected industrial controllers (PLCs). This could result in the unauthorized exposure of sensitive operational data, including device names and recorded sensor values, without requiring a login.
Technical details
A SQL injection vulnerability exists in the TDengine DAQ storage connector within `server/runtime/storage/tdengine/index.js`. The `escapeTdString` function correctly doubles single quotes but fails to escape backslashes. Because TDengine's SQL parser interprets a backslash followed by a single quote as a literal quote, an attacker can provide a crafted payload (e.g., using `\'`) to break out of the string literal and append arbitrary SQL commands. This can be triggered via unauthenticated GET requests to `/api/daq` or through Socket.IO `DAQ_QUERY` events. The vulnerability allows unauthorized reading of the `fuxa.meters` table. The issue is fixed in version 1.3.2.
Affected products
- frangoteam FUXA <= 1.1.14-1243
Timeline
- 2026-05-29: disclosed: Initial disclosure to vendor
- 2026-06-08: advisory: GitHub Advisory published
- 2026-06-08: patched: Fix released in version 1.3.2