CVE-2026-47720: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in frangoteam FUXA
CVE-2026-47720 is a SQL injection vulnerability in FUXA, a web-based SCADA/HMI/Dashboard software. Versions prior to 1.3.2 have an issue in the TDengine DAQ storage connector where backslashes are not properly escaped in SQL queries. This allows a remote unauthenticated attacker to inject SQL via crafted requests, potentially exposing historical PLC tag values, device identifiers, and device names. The vulnerability is fixed in version 1.3.2.
AI Analysis
Technical Summary
FUXA versions before 1.3.2 contain a SQL injection vulnerability in the TDengine DAQ storage connector's escapeTdString function. This function doubles single quotes but fails to escape backslashes, enabling an attacker to craft a sids tag identifier in GET /api/daq or the Socket.IO DAQ_QUERY event. The improperly escaped backslash and quote sequence is interpreted as SQL syntax by TDengine, allowing the injection of queries that can retrieve all rows from the fuxa.meters table. This exposes sensitive historical data including PLC tag values, device identifiers, and device names even when authentication is enabled. The issue is resolved in version 1.3.2.
Potential Impact
An unauthenticated remote attacker can exploit this vulnerability to perform SQL injection and retrieve sensitive information from the fuxa.meters database table. The exposed data includes historical PLC tag values, device identifiers, and device names. The vulnerability does not allow modification or deletion of data (no integrity or availability impact), but confidentiality is impacted.
Mitigation Recommendations
Upgrade FUXA to version 1.3.2 or later, where this SQL injection vulnerability is fixed. No other mitigation is required as the fix addresses the root cause.
CVE-2026-47720: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in frangoteam FUXA
Description
CVE-2026-47720 is a SQL injection vulnerability in FUXA, a web-based SCADA/HMI/Dashboard software. Versions prior to 1.3.2 have an issue in the TDengine DAQ storage connector where backslashes are not properly escaped in SQL queries. This allows a remote unauthenticated attacker to inject SQL via crafted requests, potentially exposing historical PLC tag values, device identifiers, and device names. The vulnerability is fixed in version 1.3.2.
CVSS v3.1
Score 5.3medium
Affected software
frangoteam
FUXA
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
FUXA versions before 1.3.2 contain a SQL injection vulnerability in the TDengine DAQ storage connector's escapeTdString function. This function doubles single quotes but fails to escape backslashes, enabling an attacker to craft a sids tag identifier in GET /api/daq or the Socket.IO DAQ_QUERY event. The improperly escaped backslash and quote sequence is interpreted as SQL syntax by TDengine, allowing the injection of queries that can retrieve all rows from the fuxa.meters table. This exposes sensitive historical data including PLC tag values, device identifiers, and device names even when authentication is enabled. The issue is resolved in version 1.3.2.
Potential Impact
An unauthenticated remote attacker can exploit this vulnerability to perform SQL injection and retrieve sensitive information from the fuxa.meters database table. The exposed data includes historical PLC tag values, device identifiers, and device names. The vulnerability does not allow modification or deletion of data (no integrity or availability impact), but confidentiality is impacted.
Mitigation Recommendations
Upgrade FUXA to version 1.3.2 or later, where this SQL injection vulnerability is fixed. No other mitigation is required as the fix addresses the root cause.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-19T21:29:25.482Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a84baf7c6e8be0332afda05
Added to database: 08/18/2026, 20:05:11 UTC
Last enriched: 09/11/2026, 21:03:20 UTC
Last updated: 10/02/2026, 02:46:04 UTC
Views: 53
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.