PatchSiren

Frauscher Sensortechnik CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Frauscher Sensortechnik CVE published 2026-08-20

CVE-2026-14953

A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges using the endpoint /api/user/fetch-all.php. This vulnerability affects user account management and access control. The CVSS score for this vulnerability is 5.3, indicating a MEDIUM severity. Administrators and security teams should review the CVE record and NVD entry for more informatio [truncated]

HIGH Frauscher Sensortechnik CVE published 2026-08-20

CVE-2026-14952

An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users. The vulnerability allows unauthenticated remote attackers [truncated]

HIGH Frauscher Sensortechnik CVE published 2026-08-20

CVE-2026-14951

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-20T09:16:47.597Z and has not been modified since then. Organizations using the FDS Web interface should prioritize patching this vulnerability due to its high CVSS score of 8.6 and potential impact on authenticated users. A low-privileged remote attacker can cause authenticated users to perform unin [truncated]

CRITICAL Frauscher Sensortechnik CVE published 2026-08-20

CVE-2026-14950

An unauthenticated remote attacker with a valid session identifier can continue using the session after it should have expired, increasing the risk associated with stolen, leaked, shared, or unattended sessions and potentially enabling unauthorized continued access to the FDS web interface. This vulnerability affects the FDS web interface, specifically its session management component. The risk is heighte [truncated]

HIGH Frauscher Sensortechnik CVE published 2026-08-20

CVE-2026-14949

A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by the application. This high-severity vulnerability in Frauscher Sensortechnik's FDS 102 product allows low-privileged remote attackers to create new accounts with arbit [truncated]

HIGH Frauscher Sensortechnik CVE published 2026-08-20

CVE-2026-14948

A low-privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives. This vulnerability, CVE-2026-14948, was published on 2026-08-20 and has a CVSS score of 8.7, classified as HIGH severity. The vulnerability affects web applications with [truncated]

HIGH Frauscher Sensortechnik CVE published 2026-08-20

CVE-2026-14947

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-20T09:16:46.977Z and has not been modified since then. This high-privileged remote attacker vulnerability allows malicious ZIP archive uploads with directory traversal sequences, potentially leading to arbitrary code execution due to improper validation of archive entry paths before writing files to [truncated]

HIGH Frauscher Sensortechnik CVE published 2026-08-20

CVE-2026-14946

CVE-2026-14946 is a high severity vulnerability affecting a specific product or component, potentially allowing high privileged remote attackers to achieve arbitrary code execution due to improper file type validation. This vulnerability has a CVSS score of 8.6 and could result in full system compromise if exploited. Security teams and administrators should review the official CVE record and apply vendor [truncated]