CVE-2026-67440: Frangoteam Fuxa
Medium severity, CVSS 6.9. EPSS: 0.5% chance of exploitation in the next 30 days.
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the DEVICE_BROWSE, DEVICE_NODE_ATTRIBUTE, HOST_INTERFACES, and DEVICE_TAGS_REQUEST handlers in server/runtime/index.js return device-discovery, node-attribute, host-network-interface, and device-tag metadata without isSocketAdminAuthorized when secureEnabled is true. A remote unauthenticated or guest user can invoke these metadata-oriented Socket.IO events and collect system-discovery information that is not required for normal public HMI viewing, while ordinary device status, value, alarm, and dashboard events remain intentionally public. This issue is fixed in version 1.3.3.
Affected products
- Frangoteam Fuxa: before 1.3.3 (fixed in 1.3.3)
Published 2026-08-18. Last modified 2026-09-09.