Skip to content

Known CVE

FUXA <= 1.2.7 - Hardcoded JWT Secret Authentication Bypass

FUXA v1.2.7 contains a hardcoded credentials vulnerability caused by use of a hard-coded secret key in server/api/jwt-helper.js, letting remote attackers forge admin tokens and bypass authentication, exploit requires no special conditions.

CVE-2025-69971

Critical2025CVSS 9.8CWE-321

cve2025 · fuxa · frangoteam · auth-bypass · hardcoded-credentials · jwt · scada · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website