S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Feb 22, 2026

CVE-2025-69971 Scanner

CVE-2025-69971 Scanner - Jwt Secret Authentication Bypass in FUXA

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-69971
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-coded secret key to sign and verify JWT Tokens. This allows remote attackers to forge valid admin tokens and bypass authentication to gain full administrative access.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 5, 2026View on NVD →
Detail

FUXA is a software platform developed by Frangoteam that is commonly used in industrial automation settings. It allows users to create and manage human-machine interface (HMI) systems and supervisory control and data acquisition (SCADA) environments, which are critical for monitoring and controlling industrial processes. FUXA is often deployed in factories, production floors, and industrial settings that require real-time monitoring of machinery and systems. The platform provides an intuitive interface for developing dashboards and visualization tools to give operators insight into their processes. Due to its role in industrial settings, FUXA is typically used by engineers, system integrators, and industrial operators who require a reliable and efficient way to manage their infrastructure. With the increasing digitization of industrial operations, FUXA serves as a crucial component in the smart management of automated systems.

This scanner detects a hard-coded secret key vulnerability in FUXA that allows attackers to bypass authentication mechanisms. The vulnerability arises from a hard-coded key in the jwt-helper.js file of the software, which can be exploited to forge admin tokens. This flaw potentially allows unauthorized individuals to gain increased privileges and take control of the system without needing valid user credentials. Hard-coded credentials in software applications are a known security risk, as they can be discovered and exploited by attackers with knowledge of the application code or its behavior. This specific vulnerability requires no special conditions to exploit, making it particularly dangerous. Attackers who successfully leverage this security flaw can perform malicious actions with the acquired administrative access.

The vulnerability in question is embedded in the jwt-helper.js file in older versions of FUXA, where a static secret key is employed for generating JWT tokens. The scanner checks the HTTP status response from the vulnerable endpoint, the presence of JSON data in responses, and specific content that indicates a successful access to application components. It flags instances where these conditions are met, indicating potential exploitation opportunities due to these coded secrets. By exploiting this flaw, attackers can simulate requests with spoofed tokens that appear valid to the system. The only indicator that access has been gained is typically through logs or abnormal system behavior, which is why detection is essential.

If exploited, this vulnerability could allow attackers to gain unauthorized access to the entire system, escalating to full administrative control. This can lead to significant operational disruptions in an industrial setting, including unauthorized data access, modification of HMI or SCADA configurations, and potentially shutting down or damaging industrial processes. The misuse of administrative privileges gained through this bypass can result in loss of data integrity, confidentiality, and system availability. Moreover, in critical infrastructure scenarios, the exploitation of such a vulnerability could have cascading effects, causing physical consequences due to deactivation or misuse of machinery and control systems.

REFERENCES

Solution Advice
  • Update to the latest version of FUXA that removes the hard-coded secret keys.
  • Conduct a thorough security code audit to identify and remediate other potential hardcoded credentials.
  • Implement robust security mechanisms such as encrypted environment variables to manage credentials securely.
  • Regularly monitor systems for unusual activities indicative of unauthorized access attempts.
  • Educate and enforce secure coding practices among development teams to avoid hardcoding secrets in the future.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.