FUXA Authentication Bypass Vulnerability in Node-RED Plugin Allowing Unauthenticated Remote Code Execution

Vulnerability

An authentication bypass vulnerability has been identified in FUXA versions 1.2.8 prior to 1.2.11. When the Node-RED plugin is enabled, this vulnerability allows an unauthenticated, remote attacker to execute arbitrary code on the server. The issue arises from inadequate authentication checks on the Node-RED deployment API, particularly at the '/nodered/flows' endpoint. Exploitation of this vulnerability could lead to a full system compromise, especially in environments connected to ICS/SCADA systems.

Impact

Exploitation of this vulnerability allows for unauthenticated remote code execution on the server, with potential for full system compromise, particularly in connected ICS/SCADA environments.

Reproduction

To reproduce this vulnerability, send a request to the '/nodered/flows' endpoint while the Node-RED plugin is enabled. The request can bypass authentication checks, granting access to the Node-RED deployment API. Once access is obtained, submit a malicious flow configuration to execute arbitrary code on the server.

Remediation

Users are advised to update FUXA to version 1.2.11 or later, where this vulnerability has been patched.

Added: Feb 10, 2026, 3:09 AM
Updated: Feb 10, 2026, 3:09 AM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
7.5
exploitability
7.2
remediation
7.7
relevance
2.9
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.