Executive brief
Frauscher FDS102 is a diagnostic system used to monitor and configure railway signaling infrastructure. A low-privileged attacker can download error logs containing unencrypted session identifiers and use them to hijack active administrator sessions without knowing passwords, gaining full control over critical railway safety systems.
Technical details
The vulnerability is an insertion of sensitive information into log files (CWE-532) affecting Frauscher FDS102 web interface. Session identifiers for authenticated users are stored in plaintext within downloadable error log archives. A low-privileged remote attacker with valid credentials can download these logs, extract active session tokens, and reuse them to hijack administrative sessions without authentication or password knowledge. The attack is unauthenticated in terms of the hijack itself; only initial log download requires low-privilege access. The vulnerability affects versions 2.0.0 through 2.13.3; remediation is available in version 2.14.0.
Affected products
- Frauscher Sensortechnik GmbH FDS102 2.0.0 through 2.13.3
Timeline
- 2026-08-20: disclosed
- 2026-08-25: advisory: CVE-2026-14948 published with CVSS 8.8