Browse all 8 CVE security advisories affecting frangoteam. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Frangoteam develops security testing tools focused on web application vulnerability assessment, with their core use case being automated penetration testing for identifying exploitable flaws. Historically, their tools have commonly uncovered remote code execution, cross-site scripting, and privilege escalation vulnerabilities across various applications. While no major public security incidents have been directly attributed to frangoteam's tools, their CVE record indicates a consistent pattern of discovering critical flaws in widely deployed systems. The team's approach emphasizes comprehensive scanning capabilities, though their tools have occasionally been misused for unauthorized testing, highlighting the dual-use nature of security research platforms.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-25895 | FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API — FUXACWE-22 | 7.5AI | HighAI | 2026-02-09 |
| CVE-2026-25894 | FUXA Unauthenticated Remote Code Execution via Hardcoded JWT Secret in Default Configuration — FUXACWE-321 | 9.8AI | CriticalAI | 2026-02-09 |
| CVE-2026-25893 | FUXA Unauthenticated Remote Code Execution via Admin JWT Minting — FUXACWE-285 | 9.8AI | CriticalAI | 2026-02-09 |
| CVE-2026-25951 | FUXA has a Path Traversal Sanitization Bypass — FUXACWE-22 | 7.2AI | HighAI | 2026-02-09 |
| CVE-2026-25939 | FUXA Unauthenticated Remote Arbitrary Scheduler Write — FUXACWE-862 | 9.3AI | CriticalAI | 2026-02-09 |
| CVE-2026-25938 | FUXA Unauthenticated Remote Code Execution in Node-RED Integration — FUXACWE-290 | 9.8AI | CriticalAI | 2026-02-09 |
| CVE-2026-25751 | FUXA Unauthenticated Exposure of Plaintext Database Credentials — FUXACWE-306 | 9.8AI | CriticalAI | 2026-02-06 |
| CVE-2026-25752 | FUXA Unauthenticated Remote Arbitrary Device Tag Write — FUXACWE-862 | 7.5AI | HighAI | 2026-02-06 |
This page lists every published CVE security advisory associated with frangoteam. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.