CVE-2026-14952: Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is offering files with sensitive information for download without requiring authentication

Published Aug 20, 2026
·
Updated

An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users.

Affected Software

1 affected component
Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2

Event History

Aug 20, 2026
CVE Published
via MITRE·08:19 AM
Data Sourced
via MITRE·08:19 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What does an attacker need to exploit this issue?

An attacker only needs network access to the FDS Web server. No authentication, valid session, user interaction, or special conditions are required to retrieve exposed files over HTTP.

2

Which resources should defenders check for unintended public access?

Defenders should verify whether /FdsBackup.zip and files under /downloads/* can be retrieved directly over HTTP without a valid session. Exposure of these resources can disclose detailed railway signaling and track-layout information.

3

Who is exposed to this vulnerability?

Deployments of Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 are exposed when their FDS Web server is reachable by an unauthenticated remote party. The issue concerns unauthenticated access to downloadable backup and other files.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203