Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-078/ |
|
Thu, 20 Aug 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users. | |
| Title | Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is offering files with sensitive information for download without requiring authentication | |
| First Time appeared |
Frauscher Sensortechnik
Frauscher Sensortechnik fds 102 |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:frauscher_sensortechnik:fds_102:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Frauscher Sensortechnik
Frauscher Sensortechnik fds 102 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-08-20T08:19:46.783Z
Reserved: 2026-07-07T12:47:01.243Z
Link: CVE-2026-14952
No data.
Status : Received
Published: 2026-08-20T09:16:47.740
Modified: 2026-08-20T09:16:47.740
Link: CVE-2026-14952
No data.
OpenCVE Enrichment
No data.
-
CWE-306
Missing Authentication for Critical Function