PT-2026-77306 · Fuxa · Fuxa

CVE-2026-67440

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FUXA versions prior to 1.3.3
Description In the server/runtime/index.js file, the DEVICE BROWSE, DEVICE NODE ATTRIBUTE, HOST INTERFACES, and DEVICE TAGS REQUEST handlers return device-discovery, node-attribute, host-network-interface, and device-tag metadata without verifying isSocketAdminAuthorized when secureEnabled is set to true. This allows a remote unauthenticated or guest user to invoke these Socket.IO events to collect system-discovery information that is not intended for public HMI viewing.
Recommendations Update to version 1.3.3.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67440
GHSA-RH5P-M38P-2W75

Affected Products

Fuxa