Impact
The flaw in FUXA allows an unauthenticated attacker to achieve full remote code execution with root privileges through path manipulation and configuration injection. This introduces weaknesses in access control, configuration management, path traversal, and command execution, enabling arbitrary code to be run on the underlying host system.
Affected Systems
All releases from version 1.2.11 up to and including 1.3.1 of FUXA are impacted, regardless of whether Secure Mode or Node-RED Secure Auth is enabled. The vendor, frangoteam, must verify deployments running any of these binaries.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.9, indicating high severity, while its EPSS score is less than 1 %, suggesting a low current exploitation probability. It is not listed in CISA’s KEV catalog. Exploitation requires no authentication and it is inferred from the description that the attacker can craft a malicious HTTP request that abuses the platform’s path and configuration handling logic, giving the attacker root access even in the most secure configuration.
OpenCVE Enrichment
Github GHSA