Executive brief
FUXA, an open-source web-based SCADA/HMI system used for industrial automation, contains a security flaw where it uses a fixed, publicly known secret key to secure user sessions. An attacker can use this knowledge to create their own administrative credentials, allowing them to take full control of the system. This could lead to unauthorized access to industrial processes, data theft, or disruption of critical operations.
Technical details
FUXA v1.2.7 and below utilizes a hard-coded secret key within the 'server/api/jwt-helper.js' component to sign and verify JSON Web Tokens (JWT). Because this secret is static and publicly accessible in the source code, a remote, unauthenticated attacker can generate valid JWTs with administrative claims. By providing a forged token in the 'x-access-token' header, the attacker can bypass authentication mechanisms to gain full administrative access to the SCADA/HMI server. As of the advisory date, no official patch has been confirmed for version 1.2.7.
Affected products
- frangoteam FUXA <= 1.2.7
Timeline
- 2026-02-03: advisory: Initial disclosure via GitHub and NVD
- 2026-05-11: other: Advisory withdrawn as a duplicate of GHSA-c8m8-3jcr-6rj5