Executive brief
The Frauscher FDS102 is a railway signaling diagnostic system that manages access control and user permissions. A low-privileged attacker with network access can enumerate all user accounts and identify which users have administrative privileges through an unprotected API endpoint, potentially enabling social engineering or targeted privilege escalation attacks.
Technical details
The vulnerability is a direct request (forced browsing) weakness in the /api/user/fetch-all.php endpoint. A low-privileged authenticated attacker can call this endpoint to retrieve a complete list of all configured users along with their privilege levels, without requiring elevated permissions. The endpoint lacks proper authorization checks to restrict information disclosure based on user role. No user interaction is required; exploitation is straightforward network-based access via HTTP. The vulnerability affects FDS102 versions 2.0.0 through 2.13.3. A fix is available in version 2.14.0.
Affected products
- Frauscher Sensortechnik GmbH FDS102 2.0.0 through 2.13.3
Timeline
- 2026-08-20: disclosed
- 2026-08-25: patched: Fixed in version 2.14.0