CVE-2025-69985 affects FUXA 1.2.8 and earlier. The flaw is in the server/api/jwt-helper.js middleware, which improperly treats requests as trusted internal traffic when the HTTP Referer header contains the server's own address. Because this trust decision is based on attacker-controlled header data rather than cryptographic JWT validation, a remote unauthenticated attacker can spoof the Referer header to bypass authentication. After bypassing JWT checks, the attacker can access the protected /api/runscript endpoint, which accepts arbitrary JavaScript and executes it in the Node.js server context, including use of child_process.execSync. This turns the authentication bypass into pre-authentication remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository is a small standalone exploit PoC for CVE-2025-69985 against FUXA. It contains one Python code file (Exploit.py) and two Markdown documents (README.md and Use.md) that largely repeat the vulnerability description, exploitation flow, usage examples, and mitigation guidance. The Python script is the operational component. Exploit.py defines a FuxaExploit class that creates a requests session with TLS verification disabled, optional proxy support, a fixed browser-like User-Agent, and a crafted Referer header derived from the supplied base URL. The exploit targets the web API endpoint /api/runscript. A helper method, check_vulnerable(), performs a GET request to that endpoint and treats HTTP 200/401/405 as signs the endpoint exists, although this method is not actually invoked by main(). The execute() method base64-encodes an attacker-supplied command, embeds it into JavaScript, and sends JSON to /api/runscript so the target Node.js process runs require('child_process').execSync() and returns command output. Capabilities: unauthenticated remote command execution, single-command mode (-c), and pseudo-interactive shell mode (-i). The exploit is operational rather than framework-based: it provides a real payload and command execution path, but payload customization is manual through the command argument. The attack vector is web/network-based and depends on the target trusting the Referer header for authentication bypass and exposing the runscript functionality. The documentation claims affected versions are FUXA <= 1.2.8 and identifies the vulnerable logic in server/api/jwt-helper.js.
This repository is a small standalone Python proof-of-concept exploit for CVE-2025-69985 affecting FUXA <= 1.2.8. The repo contains one executable code file (exploit.py), a README with usage/testing guidance, a GPL license, and a .gitignore. The exploit is not part of a larger exploitation framework. Core capability: exploit.py performs unauthenticated remote code execution against a vulnerable FUXA web instance by abusing a Referer-based authentication bypass. It accepts a target URL and an operator-supplied command, builds a JavaScript payload that invokes Node.js child_process.execSync(), and POSTs that payload as JSON to the target's /api/runscript endpoint. The request includes a spoofed Referer header set to <base_url>/fuxa, matching the bypass condition described in the README. If the server returns HTTP 200, the script prints the response body as command output. Operational behavior: the script disables TLS certificate verification, uses a requests Session, sets Content-Type: application/json, and handles timeout/error cases with console output. The payload includes basic escaping for backslashes, quotes, backticks, and newlines before embedding the command into JavaScript. This makes the exploit usable for arbitrary single-command execution but does not provide persistence, staging, or advanced payload management. Repository purpose: demonstrate and validate the auth bypass + RCE chain against vulnerable FUXA deployments, including local Docker-based testing on port 1881. The README also documents attack flow, vulnerable logic, mitigation guidance, and example post-exploitation commands such as reading configuration files and enumerating network state.
Repository purpose: a Python proof-of-concept exploit for CVE-2025-69985 affecting FUXA (web-based SCADA/HMI) versions <= 1.2.8. The exploit leverages an authentication bypass to reach the normally protected /api/runscript endpoint and achieve remote command execution. Main exploit capabilities (CVE-2025-69985.py): - Takes a target base URL (-u) and an arbitrary command (-c). - Builds a JavaScript (Node.js) payload that uses require('child_process').execSync() to run the supplied OS command on the server. - Sends an HTTP POST to {base_url}/api/runscript with a JSON body containing the script object (code/test fields) and prints the response body as command output. - Captures stdout directly in-band; on errors, returns error message plus any stdout/stderr. - Disables TLS verification and suppresses urllib3 warnings (verify=False), enabling use against HTTPS targets with self-signed certs. Notable endpoints/targets: - Primary target endpoint: /api/runscript (HTTP POST). - Referer header points to {base_url}/fuxa. - Documentation and docker-compose suggest the common deployment port 1881. Repository structure: - CVE-2025-69985.py: standalone exploit script (entry point). - requirements.txt: Python dependencies (requests/urllib3 stack). - docker/docker-compose.yml plus .gitkeep directories: a reproducible lab environment that runs a vulnerable FUXA 1.2.8 container (frangoteam/fuxa:1.2.8) exposed on port 1881 with persistent volumes. - README.md / SECURITY.md / CONTRIBUTING.md / LICENSE.md: usage notes, policy, and licensing. Assessment: - This is an operational RCE PoC (not just detection) with a simple, user-supplied command payload and direct output retrieval. No framework integration (e.g., Metasploit/Nuclei) is present.
Repository purpose: a Python proof-of-concept exploit for CVE-2025-69985 targeting FUXA (web-based SCADA/HMI) versions ≤ 1.2.8. The exploit leverages an authentication bypass to access a protected API endpoint (/api/runscript) and achieve remote command execution. Main exploit logic (CVE-2025-69985.py): - Accepts a target base URL (-u/--url) and an OS command (-c/--cmd). - Builds a JavaScript (Node.js) payload that imports child_process and runs execSync(<cmd>) with UTF-8 encoding. - Wraps execution in try/catch to return either command output or detailed error information including stdout/stderr. - Sends an HTTP POST request to {base_url}/api/runscript with JSON body containing the script code in params.script.code and params.script.test. - Sets Content-Type: application/json and a Referer header pointing to {base_url}/fuxa. - Disables TLS verification and suppresses urllib3 warnings (verify=False), enabling use against HTTPS targets with self-signed certs. - On HTTP 200, prints the response body as the command output (in-band output capture). Exploit capabilities: - Remote, unauthenticated (bypass) command execution against vulnerable FUXA instances. - In-band output retrieval (stdout/stderr) without needing a reverse shell. - Single-shot command execution per run; no persistence or post-exploitation modules included. Repository structure: - CVE-2025-69985.py: standalone exploit script (primary entry point). - requirements.txt: Python dependencies (requests/urllib3 stack). - docker/docker-compose.yml plus placeholder directories: spins up frangoteam/fuxa:1.2.8 on port 1881 to reproduce/test the vulnerability locally. - README.md/SECURITY.md/CONTRIBUTING.md/LICENSE.md: documentation, usage examples, and policy/license. Notable observables: - Network endpoint targeted for exploitation: /api/runscript (with Referer /fuxa). - Default service port used throughout: 1881. Overall, this is an operational PoC exploit (not a framework module) that directly triggers RCE by submitting Node.js code to FUXA’s runscript API, relying on the CVE-2025-69985 authentication bypass to reach that endpoint.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.