FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' flag is commented out by default, causing the application to initialize with authentication disabled. This allows unauthenticated remote attackers to access sensitive API endpoints, modify projects, and control industrial equipment immediately after installation.
Metrics
Affected Vendors & Products
References
History
Tue, 03 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' flag is commented out by default, causing the application to initialize with authentication disabled. This allows unauthenticated remote attackers to access sensitive API endpoints, modify projects, and control industrial equipment immediately after installation. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-02-03T17:40:20.202Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-69970
No data.
Status : Received
Published: 2026-02-03T18:16:17.260
Modified: 2026-02-03T18:16:17.260
Link: CVE-2025-69970
No data.
OpenCVE Enrichment
No data.