FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trusts the HTTP "Referer" header to validate internal requests. A remote unauthenticated attacker can bypass JWT authentication by spoofing the Referer header to match the server's host. Successful exploitation allows the attacker to access the protected /api/runscript endpoint and execute arbitrary Node.js code on the server.
PoC: CVE-2025-69985
CVE-2025-69985: FUXA ≤1.2.8 Auth Bypass + RCE via /api/runscript
PoC: CVE-2025-69985-FUXA-Exploit
CVE-2025-69985 is a critical authentication bypass vulnerability in FUXA (open-source web-based SCADA/HMI software) affecting versions ≤ 1.2.8.
PoC: CVE-2025-69985
Exploit CVE-2025-69985 to bypass authentication and execute remote commands on FUXA versions ≤ 1.2.8 via the /api/runscript endpoint.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free