CVE-2026-25895 is a critical vulnerability in FUXA, a web-based SCADA/HMI software. With a CVSS score of 9.5, it involves missing authentication for a critical function and path traversal, allowing unauthenticated remote attackers to write arbitrary files and achieve remote code execution.