An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-078/ |
|
History
Thu, 20 Aug 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users. | |
| Title | Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is offering files with sensitive information for download without requiring authentication | |
| First Time appeared |
Frauscher Sensortechnik
Frauscher Sensortechnik fds 102 |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:frauscher_sensortechnik:fds_102:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Frauscher Sensortechnik
Frauscher Sensortechnik fds 102 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-08-20T08:19:46.783Z
Reserved: 2026-07-07T12:47:01.243Z
Link: CVE-2026-14952
No data.
Status : Received
Published: 2026-08-20T09:16:47.740
Modified: 2026-08-20T09:16:47.740
Link: CVE-2026-14952
No data.
OpenCVE Enrichment
No data.
Weaknesses