Executive brief
Frauscher FDS102 is a diagnostic system used for railway signalling and track management. An attacker with a stolen or leaked session identifier can continue using that session indefinitely after it should have expired, enabling unauthorized access to sensitive railway infrastructure control interfaces and data.
Technical details
The vulnerability is an insufficient session expiration flaw (CWE-613) in the FDS102 web interface. An unauthenticated attacker in possession of a valid session identifier can continue using the session after its intended expiration time, without needing to re-authenticate. This is a network-reachable attack requiring only a leaked or stolen session token. Successful exploitation enables unauthorized continued access to the FDS web interface and potential access to sensitive railway signalling and track layout information. The vendor has released a patch in version 2.14.0.
Affected products
- Frauscher Sensortechnik GmbH FDS102 2.0.0 through 2.13.3
Timeline
- 2026-08-20: disclosed
- 2026-08-25: patched: Version 2.14.0 available