Remote Code Execution in FUXA Process Visualization Software
CVE-2026-43945
8.9HIGH
What is CVE-2026-43945?
FUXA is a widely used web-based Process Visualization tool that helps in SCADA/HMI/Dashboard functionalities. A security flaw has been identified in versions 1.2.11 through 1.3.0, allowing remote attackers to execute arbitrary code with root privileges without authentication. This exploitation is possible even in scenarios where Secure Mode and Node-RED Secure Auth are activated, presenting substantial security risks to systems reliant on FUXA. Users are advised to upgrade to version 1.3.1, which addresses this critical vulnerability.
Affected Version(s)
FUXA >= 1.2.11, < 1.3.1
