CVE-2025-69970

Source
https://cve.org/CVERecord?id=CVE-2025-69970
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-69970.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-69970
Aliases
Published
2026-02-03T00:00:00Z
Modified
2026-07-15T01:49:04.367638700Z
Severity
  • 9.3 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' flag is commented out by default, causing the application to initialize with authentication disabled. This allows unauthenticated remote attackers to access sensitive API endpoints, modify projects, and control industrial equipment immediately after installation.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/69xxx/CVE-2025-69970.json",
    "cna_assigner": "mitre"
}
References

Affected packages

Git / github.com/frangoteam/fuxa

Affected ranges

Type
GIT
Repo
https://github.com/frangoteam/fuxa
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "1.2.7"
        },
        {
            "last_affected": "1.2.7"
        }
    ],
    "source": "CPE_STRING",
    "cpe": "cpe:2.3:a:frangoteam:fuxa:1.2.7:*:*:*:*:*:*:*"
}

Affected versions

1.*
1.2.7
v1.*
v1.2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-69970.json"