Junglewise Threat Intelligence

CVE-2026-14953: Frauscher FDS102 user enumeration via API endpoint

CVE-2026-14953 · Severity: medium · CVSS 4.3 · Published 2026-08-20

Technologies: Frauscher Sensortechnik GmbH FDS102. Vendors: Frauscher Sensortechnik GmbH.

Executive brief

The Frauscher FDS102 is a railway signaling diagnostic system that manages access control and user permissions. A low-privileged attacker with network access can enumerate all user accounts and identify which users have administrative privileges through an unprotected API endpoint, potentially enabling social engineering or targeted privilege escalation attacks.

Technical details

The vulnerability is a direct request (forced browsing) weakness in the /api/user/fetch-all.php endpoint. A low-privileged authenticated attacker can call this endpoint to retrieve a complete list of all configured users along with their privilege levels, without requiring elevated permissions. The endpoint lacks proper authorization checks to restrict information disclosure based on user role. No user interaction is required; exploitation is straightforward network-based access via HTTP. The vulnerability affects FDS102 versions 2.0.0 through 2.13.3. A fix is available in version 2.14.0.

Affected products

  • Frauscher Sensortechnik GmbH FDS102 2.0.0 through 2.13.3

Timeline

  • 2026-08-20: disclosed
  • 2026-08-25: patched: Fixed in version 2.14.0

References

Related threats