Executive brief
Frauscher FDS102 is a railway diagnostic system used to monitor signaling and track infrastructure. An unauthenticated attacker can download sensitive files including system backups and railway layout information directly over HTTP, exposing critical infrastructure data to unauthorized access.
Technical details
The vulnerability is a missing authentication control (CWE-306) that allows unauthenticated HTTP requests to retrieve sensitive files from the FDS102 web server, including /FdsBackup.zip and files under /downloads/*. The web server fails to enforce authentication checks on these critical endpoints, allowing an unauthenticated remote attacker to access detailed railway signaling and track layout information over the network without requiring a valid session. No user interaction or special privileges are required; the attack is a simple HTTP GET request. Patches are available in FDS102 version 2.14.0 and later.
Affected products
- Frauscher Sensortechnik GmbH FDS102 2.0.0 to 2.13.3
Timeline
- 2026-08-20: disclosed
- 2026-08-25: advisory
- 2026: patched: Fixed in FDS102 v2.14.0