Vulnerabilidades em Frangoteam
23 resultadosAnálise Vexday
Frangoteam apresenta presença mínima na base de vulnerabilidades com apenas 1 CVE registrado, publicado recentemente (últimos 90 dias) e sem evidência de exploração ativa no cenário. A vulnerabilidade identificada refere-se a autenticação e criptografia (CWE-290), com severidade abaixo do nível crítico, representando risco baixo no contexto atual.
CVE-2026-25939CRITICALFUXA Unauthenticated Remote Arbitrary Scheduler WriteEPSS 11.7%CVE-2026-25895CRITICALFUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload APIEPSS 11.2%CVE-2026-47717HIGHFUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device ConfigurationsEPSS 1.4%CVE-2026-25951HIGHFUXA has a Path Traversal Sanitization BypassEPSS 1.3%CVE-2026-25938CRITICALFUXA Unauthenticated Remote Code Execution in Node-RED IntegrationEPSS 1.0%CVE-2026-43947HIGHFUXA Vulnerable to Unauthenticated Remote Code Execution via Script Test Mode Authorization BypassEPSS 0.9%CVE-2026-43945HIGHFUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration InjectionEPSS 0.8%CVE-2026-25894CRITICALFUXA Unauthenticated Remote Code Execution via Hardcoded JWT Secret in Default ConfigurationEPSS 0.8%CVE-2026-25893CRITICALFUXA Unauthenticated Remote Code Execution via Admin JWT MintingEPSS 0.7%CVE-2026-67443CRITICALFUXA: Unauthenticated guest JWT bypasses Node-RED secure-mode authorization gate (Remote Script Execution)EPSS 0.6%CVE-2026-13207HIGHFrangoteam FUXA SCADA/HMI Authentication Bypass by SpoofingEPSS 0.6%CVE-2026-47719HIGHFUXA: Unauthenticated SSRF via Socket.IO DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY with response readingEPSS 0.6%CVE-2026-43946HIGHFUXA has an unauthenticated arbitrary tag value disclosure via /api/getTagValueEPSS 0.6%CVE-2026-25752CRITICALFUXA Unauthenticated Remote Arbitrary Device Tag WriteEPSS 0.5%CVE-2026-47720MEDIUMFUXA: SQL injection in TDengine DAQ connector via backslash bypass of escapeTdStringEPSS 0.5%CVE-2026-67440MEDIUMFUXA: Unauthenticated Socket.IO read eventsEPSS 0.5%CVE-2026-65984HIGHFUXA: JWT lifecycle flaws allow deleted or demoted users to retain privileged sessionsEPSS 0.5%CVE-2026-72586HIGHfrangoteam FUXA - Missing Authentication on DAQ_QUERY Socket.IO Event HandlerEPSS 0.4%CVE-2026-47718MEDIUMFUXA provides guest and invalid-token access to protected read APIs in secure modeEPSS 0.3%CVE-2026-65985MEDIUMFUXA: SSRF hardening for `device-webapi-request`EPSS 0.3%