Search
Search Results (8 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-14953 | 1 Frauscher Sensortechnik | 1 Fds 102 | 2026-08-20 | 4.3 Medium |
| A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges using the endpoint /api/user/fetch-all.php. | ||||
| CVE-2026-14952 | 1 Frauscher Sensortechnik | 1 Fds 102 | 2026-08-20 | 7.5 High |
| An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users. | ||||
| CVE-2026-14951 | 1 Frauscher Sensortechnik | 1 Fds 102 | 2026-08-20 | 8 High |
| An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using malicious web pages. | ||||
| CVE-2026-14950 | 1 Frauscher Sensortechnik | 1 Fds 102 | 2026-08-20 | 9.8 Critical |
| An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. This increases the risk associated with stolen, leaked, shared, or unattended sessions and may enable unauthorized continued access to the FDS web interface. | ||||
| CVE-2026-14949 | 1 Frauscher Sensortechnik | 1 Fds 102 | 2026-08-20 | 6.5 Medium |
| A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by the application. | ||||
| CVE-2026-14948 | 1 Frauscher Sensortechnik | 1 Fds 102 | 2026-08-20 | 8.8 High |
| A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives. | ||||
| CVE-2026-14947 | 1 Frauscher Sensortechnik | 1 Fds 102 | 2026-08-20 | 7.2 High |
| A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extraction directory and write files to arbitrary locations on the server, potentially achieve arbitrary code execution due to improper validation of archive entry paths before writing files to disk which could result in full system compromise. | ||||
| CVE-2026-14946 | 1 Frauscher Sensortechnik | 1 Fds 102 | 2026-08-20 | 7.2 High |
| A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to achieve arbitrary code execution due to improper file type validation which could result in full system compromise. | ||||
Page 1 of 1.