Frangoteam FUXA SCADA/HMI

MonitorCVSS 7.5ICS-CERT ICSA-26-181-02Jun 30, 2026
Mitsubishi ElectricEnergyManufacturing
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

FUXA SCADA/HMI versions 1.3.1 and earlier contain a user enumeration vulnerability that allows unauthenticated remote attackers to discover all user accounts and their assigned roles on a vulnerable instance. This information disclosure occurs through unprotected API endpoints or configuration interfaces that expose account and privilege information without authentication checks.

What this means
What could happen
An unauthenticated attacker on your network could enumerate all user accounts and their roles in your FUXA SCADA/HMI system, compromising operational security by revealing who has access to control critical processes.
Who's at risk
Energy and manufacturing organizations using FUXA SCADA/HMI for process visualization and control. This affects any facility that relies on FUXA for monitoring and managing industrial processes, PLCs, and critical equipment.
How it could be exploited
An attacker sends network requests to the FUXA instance without any credentials to query user account and role information. This information disclosure could then be used to plan further attacks targeting specific privileged accounts.
Prerequisites
  • Network access to the FUXA SCADA/HMI service port (typically HTTP/HTTPS)
  • FUXA version 1.3.1 or earlier running and accessible
remotely exploitableno authentication requiredlow complexityinformation disclosure to unauthenticated users
Exploitability
Unlikely to be exploited — EPSS score 0.6%
Affected products (1)
ProductAffected VersionsFix Status
FUXA SCADA/HMI≤ 1.3.1No fix yet
Remediation & Mitigation
0/3
Do now
0/1
HARDENINGRestrict network access to FUXA SCADA/HMI to authorized engineering workstations and control network segments only using firewall rules
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpdate FUXA to version 1.3.2 or later
Long-term hardening
0/1
HARDENINGImplement network segmentation to isolate FUXA instances from untrusted networks and the internet
API: /api/v1/advisories/27c9b7c3-2ce9-45ec-80d5-0840803c0906

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Frangoteam FUXA SCADA/HMI | CVSS 7.5 - OTPulse