TL;DR
Frauscher patched eight flaws in its FDS102 railway diagnostic system on August 20, 2026. The most severe, CVE-2026-14950, scores 9.8 on CVSS 3.1. It lets an attacker keep unauthorized continued access to the web interface. These Frauscher FDS102 vulnerabilities are fixed in version 2.14.0.
- Total: 8 CVEs
- Severity: 1 Critical · 6 High · 1 Medium
- Actively exploited: None confirmed
- Highest severity: 9.8 (Critical · CVSSv3) — CVE-2026-14950
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS | Fixed in | Status |
|---|
Why it matters
FDS102 is a diagnostic system for Frauscher track-detection equipment. It runs alongside the FAdC axle counter used in railway signalling. A compromise here can expose track layout data and signalling details.
CERT@VDE coordinated the disclosure. The advisory carries a TLP:WHITE label, so anyone can read it.
How the attacks work
The eight issues span several weakness types. A few stand out.
CVE-2026-14950: session never expires
This is the critical flaw. The session expiration logic is broken. As a result, an attacker holding a valid session ID can keep using it after it should have ended. That enables unauthorized continued access from stolen, shared, or unattended sessions.
CVE-2026-14946 and CVE-2026-14947: remote code execution
Both let a high-privileged user run code on the server. One abuses an unrestricted file upload. The other uses a malicious ZIP with path traversal to write files outside the target folder.
CVE-2026-14952: exposed backup files
This flaw needs no login at all. An attacker can pull a backup archive and other files directly over HTTP. Those files reveal railway signalling and track layout information.
Affected versions
The flaws affect FDS102 releases from 2.0.0 up to and including 2.13.3. Specific bugs map to specific version ranges. The advisory reports no in-the-wild exploitation and no public proof-of-concept.
Patch and mitigation steps
Update to FDS102 v2.14.0. The vendor and the CERT@VDE advisory both list this fix. Operators should also restrict device access to authorized personnel. Frauscher further advises placing FDS102 on a category 2 network, with extra controls on category 3 networks.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.