PT-2026-77305 · Fuxa · Fuxa

CVE-2026-65985

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions FUXA versions prior to 1.3.3
Description The device-webapi-request Socket.IO handler in server/runtime/index.js allows an authenticated non-admin runtime user to control the property.address variable. This leads to a Server-Side Request Forgery (SSRF), where the server issues an outbound HTTP or HTTPS request and returns the response body to the requester. An attacker can use the server as a read SSRF oracle to access reachable internal services or cloud metadata endpoints.
Recommendations Update to version 1.3.3.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65985
GHSA-WRG6-49WH-46PW

Affected Products

Fuxa