Remote File Exposure in FDS Web Server by Vendor
CVE-2026-14952
8.7HIGH
What is CVE-2026-14952?
The FDS Web Server is susceptible to an unauthenticated remote access vulnerability that allows attackers to retrieve sensitive files directly over HTTP. Compromised files include the backup archive at /FdsBackup.zip and other critical information within the /downloads/* directory. This exposure can lead to the unauthorized disclosure of railway signaling and track layout details, posing significant risks to security.
Affected Version(s)
FDS 102 2.1.0 <= 2.13.3
