← All Advisories

FUXA SCADA Socket.IO Request Handlers Skip Authorization, Allowing Unauthenticated Attackers to Initiate Requests to Arbitrary HTTP, OPC UA, and ODBC Destinations

Last refreshed2026-09-30

Status: NEW  |  Advisory ID: CVE-2026-47719

Key Details

CVECVE-2026-47719
CVSS Score / Version8.2 (High) / CVSS v3.1
Updated2026-09-09
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is low; availability impact is none.
Classified asCWE-918 (Server-Side Request Forgery (SSRF))

What to Know

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY Socket.IO handlers in server/runtime/index.js omit isSocketWriteAuthorized and accept attacker-controlled property.address or endpoint connection data. A remote unauthenticated attacker can make server/runtime/devices/httprequest/index.js call axios.get against arbitrary HTTP or HTTPS destinations, connect to reachable OPC UA or ODBC services, and receive results through the corresponding Socket.IO event. This read SSRF oracle can expose cloud instance metadata, internal administrative services, industrial endpoints, and ODBC data reachable from the FUXA host, including when secureEnabled is true. This issue is fixed in version 1.3.2. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-47719
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-47719