24h | 7d | 30d

Overview

  • Frauscher Sensortechnik
  • FDS 102

20 Aug 2026
Published
20 Aug 2026
Updated

CVSS v4.0
HIGH (8.6)
EPSS
0.16%

KEV

Description

An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using malicious web pages.

Statistics

  • 1 Post

Last activity: 9 hours ago

Fediverse

Profile picture fallback

VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

frauscher.csaf-tp.certvde.com/

  • 0
  • 0
  • 0
  • 9h ago

Overview

  • Frauscher Sensortechnik
  • FDS 102

20 Aug 2026
Published
20 Aug 2026
Updated

CVSS v4.0
MEDIUM (5.3)
EPSS
0.20%

KEV

Description

A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges using the endpoint /api/user/fetch-all.php.

Statistics

  • 1 Post

Last activity: 9 hours ago

Fediverse

Profile picture fallback

VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

frauscher.csaf-tp.certvde.com/

  • 0
  • 0
  • 0
  • 9h ago

Overview

  • Frauscher Sensortechnik
  • FDS 102

20 Aug 2026
Published
20 Aug 2026
Updated

CVSS v4.0
HIGH (8.6)
EPSS
0.52%

KEV

Description

A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to achieve arbitrary code execution due to improper file type validation which could result in full system compromise.

Statistics

  • 1 Post

Last activity: 9 hours ago

Fediverse

Profile picture fallback

VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

frauscher.csaf-tp.certvde.com/

  • 0
  • 0
  • 0
  • 9h ago

Overview

  • Frauscher Sensortechnik
  • FDS 102

20 Aug 2026
Published
20 Aug 2026
Updated

CVSS v4.0
HIGH (8.5)
EPSS
0.26%

KEV

Description

A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by the application.

Statistics

  • 1 Post

Last activity: 9 hours ago

Fediverse

Profile picture fallback

VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

frauscher.csaf-tp.certvde.com/

  • 0
  • 0
  • 0
  • 9h ago

Overview

  • Frauscher Sensortechnik
  • FDS 102

20 Aug 2026
Published
20 Aug 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.39%

KEV

Description

A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives.

Statistics

  • 1 Post

Last activity: 9 hours ago

Fediverse

Profile picture fallback

VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

frauscher.csaf-tp.certvde.com/

  • 0
  • 0
  • 0
  • 9h ago

Overview

  • Frauscher Sensortechnik
  • FDS 102

20 Aug 2026
Published
20 Aug 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.49%

KEV

Description

An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users.

Statistics

  • 1 Post

Last activity: 9 hours ago

Fediverse

Profile picture fallback

VDE-2026-078
Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
CVE-2026-14950, CVE-2026-14948, CVE-2026-14951, CVE-2026-14952, CVE-2026-14947, CVE-2026-14946, CVE-2026-14949, CVE-2026-14953

certvde.com/en/advisories/vde-

frauscher.csaf-tp.certvde.com/

  • 0
  • 0
  • 0
  • 9h ago
Showing 61 to 66 of 66 CVEs