CVE-2026-14952
Frauscher Sensortechnik FDS 102
An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users.
- CVSS
- 8.7
- EPSS
- 0.50% 40.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.08.20