CVE-2026-14950 (CVSS 9.8): Frauscher FDS102 Flaw Enables Unauthorized Continued Access
ID: 026fba6d-c0ab-52c4-93f4-2bdbc38416c7
STIX ID: report--026fba6d-c0ab-52c4-93f4-2bdbc38416c7
Feed Name: securityonline.info
Frauscher released fixes for eight vulnerabilities in its FDS102 railway diagnostic system (versions 2.0.0–2.13.3), the most severe being CVE-2026-14950 (CVSS 9.8) which allows sessions to never expire and enables persistent unauthorized access; other issues permit RCE via unrestricted uploads and path-traversal ZIPs and permit HTTP access to sensitive backup files. CERT@VDE coordinated disclosure, no active exploitation reported, and operators are advised to update to v2.14.0 and restrict device network access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
