SQL Injection in FUXA Web-Based SCADA/Dashboard Software
CVE-2026-47720

5.3MEDIUM

Key Information:

Vendor

Frangoteam

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-47720?

FUXA, a web-based Process Visualization software, is susceptible to an SQL injection vulnerability due to improper handling of user input in its TDengine DAQ storage connector. Specifically, the escapeTdString function fails to escape backslashes while doubling single quotes. This allows a remote unauthenticated attacker to inject crafted identifiers through specific API calls, potentially revealing all rows from the fuxa.meters table, including sensitive historical PLC tag values and device identifiers. This vulnerability has been addressed in version 1.3.2.

Affected Version(s)

FUXA < 1.3.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.