Junglewise Threat Intelligence

CVE-2026-14950: Frauscher FDS102 insufficient session expiration

CVE-2026-14950 · Severity: critical · CVSS 9.8 · Published 2026-08-20

Technologies: Frauscher Sensortechnik GmbH FDS102. Vendors: Frauscher Sensortechnik GmbH.

Executive brief

Frauscher FDS102 is a diagnostic system used for railway signalling and track management. An attacker with a stolen or leaked session identifier can continue using that session indefinitely after it should have expired, enabling unauthorized access to sensitive railway infrastructure control interfaces and data.

Technical details

The vulnerability is an insufficient session expiration flaw (CWE-613) in the FDS102 web interface. An unauthenticated attacker in possession of a valid session identifier can continue using the session after its intended expiration time, without needing to re-authenticate. This is a network-reachable attack requiring only a leaked or stolen session token. Successful exploitation enables unauthorized continued access to the FDS web interface and potential access to sensitive railway signalling and track layout information. The vendor has released a patch in version 2.14.0.

Affected products

  • Frauscher Sensortechnik GmbH FDS102 2.0.0 through 2.13.3

Timeline

  • 2026-08-20: disclosed
  • 2026-08-25: patched: Version 2.14.0 available

References

Related threats