CVE-2026-14947: Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Remote Code Execution via malicious ZIP file
A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extraction directory and write files to arbitrary locations on the server, potentially achieve arbitrary code execution due to improper validation of archive entry paths before writing files to disk which could result in full system compromise.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must be remote and already have high privileges. No user interaction is required.
What capability enables exploitation?
An attacker needs the ability to upload a ZIP archive to the affected system. The archive must contain directory traversal entry paths, such as ../, so extracted files can be written outside the intended directory.
What is the potential impact if exploitation succeeds?
The attacker may write files to arbitrary locations on the server and potentially achieve arbitrary code execution. This could result in full system compromise.