Junglewise Threat Intelligence

CVE-2026-14951: Frauscher FDS102 Cross-Site Request Forgery in web interface

CVE-2026-14951 · Severity: high · CVSS 8 · Published 2026-08-20

Technologies: Frauscher Sensortechnik GmbH FDS102. Vendors: Frauscher Sensortechnik GmbH.

Executive brief

Frauscher FDS102 is a diagnostic system used for railway signaling infrastructure. A low-privileged attacker can trick authenticated users into performing unintended actions in the FDS web interface by directing them to malicious web pages, potentially leading to unauthorized changes to critical railway signaling configuration or data.

Technical details

CVE-2026-14951 is a Cross-Site Request Forgery (CSRF) vulnerability in the Frauscher FDS102 web interface. A low-privileged authenticated attacker can craft malicious web pages that trick other authenticated users (potentially administrators) into performing unintended actions without their knowledge. The vulnerability requires user interaction (the victim must visit the attacker's page) and the victim must already be authenticated to FDS102. Successful exploitation can result in high-impact changes to the FDS102 system including modification of railway signaling configuration and data. The vendor has released a patch in FDS102 v2.14.0.

Affected products

  • Frauscher Sensortechnik GmbH FDS102 2.0.0 through 2.13.3

Timeline

  • 2026-08-20: disclosed
  • 2026-08-25: patched: Fix available in FDS102 v2.14.0

References

Related threats