FUXA <= 1.2.7 - Hardcoded JWT Secret Authentication Bypass
CVE-2025-69971
Verified
Description
FUXA v1.2.7 contains a hardcoded credentials vulnerability caused by use of a hard-coded secret key in server/api/jwt-helper.js, letting remote attackers forge admin tokens and bypass authentication, exploit requires no special conditions.
Severity
Critical
CVSS Score
9.8
Exploit Probability
2%
Affected Product
fuxa
Published Date
February 15, 2026
Template Author
trader642
CVE-2025-69971.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2025-69971
CWE ID:
cwe-321
Remediation Steps
Update to the latest version that removes hard-coded credentials.