logo

CVE-2026-14950 (CVSS 9.8): Frauscher FDS102 Flaw Enables Unauthorized Continued Access

ID: 026fba6d-c0ab-52c4-93f4-2bdbc38416c7

STIX ID: report--026fba6d-c0ab-52c4-93f4-2bdbc38416c7

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-08-20

Date Updated: 2026-08-20

Author: Do Son

...
...

Frauscher released fixes for eight vulnerabilities in its FDS102 railway diagnostic system (versions 2.0.0–2.13.3), the most severe being CVE-2026-14950 (CVSS 9.8) which allows sessions to never expire and enables persistent unauthorized access; other issues permit RCE via unrestricted uploads and path-traversal ZIPs and permit HTTP access to sensitive backup files. CERT@VDE coordinated disclosure, no active exploitation reported, and operators are advised to update to v2.14.0 and restrict device network access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.