What is CVE-2026-47720?
In FUXA SCADA software, the TDengine DAQ storage connector fails to escape backslashes in the escapeTdString function, allowing a remote unauthenticated attacker to inject malicious queries. This vulnerability affects versions prior to 1.3.2. Immediate update to version 1.3.2 or later is strongly recommended.
Azərbaycanca: FUXA SCADA proqramında TDengine DAQ storage connector-da backslash simvollarının düzgün qaçırılmaması (escape edilməməsi) səbəbindən uzaqdan autentifikasiya olunmamış hücumçu xüsusi hazırlanmış sorğu göndərə bilər. Bu zəiflik 1.3.2 versiyasından əvvəlki bütün versiyalara təsir edir. Dərhal proqramı 1.3.2 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
In which component of FUXA SCADA is the backslash escaping vulnerability present?
The vulnerability exists in the TDengine DAQ storage connector of FUXA SCADA, specifically in the escapeTdString function, due to improper escaping of backslash characters.
Which version is recommended to update to in order to mitigate CVE-2026-47720?
Since all versions prior to 1.3.2 are affected, an immediate update to version 1.3.2 or later is strongly recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.