CVE-2026-14952: Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is offering files with sensitive information for download without requiring authentication
An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
An attacker only needs network access to the FDS Web server. No authentication, valid session, user interaction, or special conditions are required to retrieve exposed files over HTTP.
Which resources should defenders check for unintended public access?
Defenders should verify whether /FdsBackup.zip and files under /downloads/* can be retrieved directly over HTTP without a valid session. Exposure of these resources can disclose detailed railway signaling and track-layout information.
Who is exposed to this vulnerability?
Deployments of Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 are exposed when their FDS Web server is reachable by an unauthenticated remote party. The issue concerns unauthenticated access to downloadable backup and other files.