Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-69985

EPSS 4.69% · P89
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-69985

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trusts the HTTP "Referer" header to validate internal requests. A remote unauthenticated attacker can bypass JWT authentication by spoofing the Referer header to match the server's host. Successful exploitation allows the attacker to access the protected /api/runscript endpoint and execute arbitrary Node.js code on the server.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
FUXA 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
FUXA是frangoteam开源的一个基于web的过程可视化软件。 FUXA 1.2.8及之前版本存在安全漏洞,该漏洞源于身份验证绕过,server/api/jwt-helper.js中间件不当信任HTTP Referer标头验证内部请求,可能导致远程未认证攻击者通过伪造Referer标头绕过JWT身份验证,进而访问受保护的/api/runscript端点并在服务器上执行任意Node.js代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2025-69985

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-69985

登录查看更多情报信息。

Same Patch Batch · n/a · 2026-02-24 · 9 CVEs total

CVE-2026-31026.3 MEDIUMexiftool PNG File MacOS.pm SetMacOSTags os command injection
CVE-2026-30676.3 MEDIUMHummerRisk Archive Extraction CommandUtils.java extractZip path traversal
CVE-2026-30666.3 MEDIUMHummerRisk Cloud Compliance Scanning PlatformUtils.java fixedCommand command injection
CVE-2026-30656.3 MEDIUMHummerRisk Cloud Task Dry-run CloudTaskService.java CommandUtils.commonExecCmdWithResult c
CVE-2026-30646.3 MEDIUMHummerRisk Cloud Task Scheduler ResourceCreateService.java command injection
CVE-2025-155893.8 LOWMuYuCMS Template Management Template.php delete_dir_file path traversal
CVE-2025-67445TOTOLINK X5000R 安全漏洞
CVE-2025-63409GCOM EPON 1GE 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2025-69985

No comments yet


Leave a comment