Executive brief
FUXA is a web-based SCADA/HMI visualization software used to monitor and control industrial processes. An unauthenticated attacker can query all historical sensor data by exploiting a missing authentication check in the DAQ_QUERY Socket.IO event, bypassing the security controls that protect other sensitive operations when security is enabled.
Technical details
FUXA contains an authentication bypass vulnerability in the DAQ_QUERY Socket.IO event handler located in server/runtime/index.js. While other sensitive Socket.IO events (DEVICE_BROWSE, HOST_INTERFACES, DEVICE_TAGS_REQUEST, etc.) correctly call isSocketAdminAuthorized to verify connection tokens when secureEnabled=true, the DAQ_QUERY handler entirely lacks this authentication check. An unauthenticated remote attacker can connect via Socket.IO and invoke DAQ_QUERY to retrieve historical sensor data without credentials. The vulnerability affects FUXA through version 1.3.3 and requires network access to the Socket.IO endpoint but no user interaction or authentication.
Affected products
- frangoteam FUXA through 1.3.3
Timeline
- 2026-08-10: disclosed