Skip to content

Secure EU

Menu
  • Home
Menu

CVE-2026-25895 – FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API

Posted on February 10, 2026
CVE ID : CVE-2026-25895

Published : Feb. 9, 2026, 11:16 p.m. | 44 minutes ago

Description : FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This affects FUXA through version 1.2.9. This issue has been patched in FUXA version 1.2.10.

Severity: 9.5 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Solution

©2026 Secure EU | Design: Newspaperly WordPress Theme