Description
An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-078/ |
|
History
Thu, 20 Aug 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users. | |
| Title | Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is offering files with sensitive information for download without requiring authentication | |
| First Time appeared |
Frauscher Sensortechnik
Frauscher Sensortechnik fds 102 |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:frauscher_sensortechnik:fds_102:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Frauscher Sensortechnik
Frauscher Sensortechnik fds 102 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-08-20T15:26:26.749Z
Reserved: 2026-07-07T12:47:01.243Z
Link: CVE-2026-14952
No data.
Status : Received
Published: 2026-08-20T09:16:47.740
Modified: 2026-08-20T16:17:07.333
Link: CVE-2026-14952
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-306
Missing Authentication for Critical Function