CyberRota Analysis
AI-GeneratedFUXA's web-based Process Visualization software is vulnerable due to improper handling of input in the TDengine DAQ storage connector, allowing remote unauthenticated attackers to exploit the escapeTdString function. This vulnerability enables attackers to inject SQL queries that can retrieve sensitive data, including historical PLC tag values and device identifiers, even with authentication enabled. Organizations using versions prior to 1.3.2 should prioritize upgrading to the latest version to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengine DAQ storage connector's escapeTdString function in server/runtime/storage/tdengine/index.js doubles single quotes but does not escape backslashes. A remote unauthenticated attacker can submit a crafted sids tag identifier through GET /api/daq or the Socket.IO DAQ_QUERY event so TDengine interprets the backslash and quote sequence as SQL syntax. The injected query can return every row from fuxa.meters, exposing historical PLC tag values, device identifiers, and device names even when FUXA authentication is enabled. This issue is fixed in version 1.3.2.