Junglewise Threat Intelligence

CVE-2026-14948: Frauscher FDS102 session hijacking via plaintext log extraction

CVE-2026-14948 · Severity: high · CVSS 8.8 · Published 2026-08-20

Technologies: Frauscher Sensortechnik GmbH FDS102. Vendors: Frauscher Sensortechnik GmbH.

Executive brief

Frauscher FDS102 is a diagnostic system used to monitor and configure railway signaling infrastructure. A low-privileged attacker can download error logs containing unencrypted session identifiers and use them to hijack active administrator sessions without knowing passwords, gaining full control over critical railway safety systems.

Technical details

The vulnerability is an insertion of sensitive information into log files (CWE-532) affecting Frauscher FDS102 web interface. Session identifiers for authenticated users are stored in plaintext within downloadable error log archives. A low-privileged remote attacker with valid credentials can download these logs, extract active session tokens, and reuse them to hijack administrative sessions without authentication or password knowledge. The attack is unauthenticated in terms of the hijack itself; only initial log download requires low-privilege access. The vulnerability affects versions 2.0.0 through 2.13.3; remediation is available in version 2.14.0.

Affected products

  • Frauscher Sensortechnik GmbH FDS102 2.0.0 through 2.13.3

Timeline

  • 2026-08-20: disclosed
  • 2026-08-25: advisory: CVE-2026-14948 published with CVSS 8.8

References

Related threats