SQL Injection in FUXA Web-Based SCADA/Dashboard Software
CVE-2026-47720
5.3MEDIUM
What is CVE-2026-47720?
FUXA, a web-based Process Visualization software, is susceptible to an SQL injection vulnerability due to improper handling of user input in its TDengine DAQ storage connector. Specifically, the escapeTdString function fails to escape backslashes while doubling single quotes. This allows a remote unauthenticated attacker to inject crafted identifiers through specific API calls, potentially revealing all rows from the fuxa.meters table, including sensitive historical PLC tag values and device identifiers. This vulnerability has been addressed in version 1.3.2.
Affected Version(s)
FUXA < 1.3.2
