Understanding industrial Cybersecurity.
-
Updated
Apr 21, 2026 - G-code
Understanding industrial Cybersecurity.
Description and exploit of CVE-2023-33831 affecting FUXA web-based Process Visualization (SCADA/HMI/Dashboard) software.
CVE-2025-69985: FUXA ≤1.2.8 Auth Bypass + RCE via /api/runscript
A fully isolated, reproducible industrial control systems (ICS) and operational technology (OT) emulation sandbox built inside GNS3, featuring OpenPLC, Fuxa HMI, and Kali Linux.
Open-source IEC 61850 MMS to Modbus TCP and MQTT gateway for Windows HMI, SCADA, relay testing, FAT/SAT, and substation automation labs.
OpenLogiTwin — a deterministic conveyor sorting cell digital twin: real Modbus TCP, soft-PLC (OpenPLC-bound), deterministic scenarios, SQLite telemetry, FUXA/Godot integration. Zero-dependency core, 52 tests, CI.
Exploit CVE-2025-69985 to bypass authentication and execute remote commands on FUXA versions ≤ 1.2.8 via the /api/runscript endpoint.
Add a description, image, and links to the fuxa topic page so that developers can more easily learn about it.
To associate your repository with the fuxa topic, visit your repo's landing page and select "manage topics."