CVE-2026-14947 PUBLISHED

Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Remote Code Execution via malicious ZIP file

Assigner: CERTVDE
Reserved: 07.07.2026 Published: 20.08.2026 Updated: 20.08.2026

A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extraction directory and write files to arbitrary locations on the server, potentially achieve arbitrary code execution due to improper validation of archive entry paths before writing files to disk which could result in full system compromise.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.6

Product Status

Vendor Frauscher Sensortechnik
Product FDS 102
Versions Default: unaffected
  • affected from 2.8.0 to 2.13.3 (incl.)

References

Problem Types

  • CWE-24 Path Traversal: '../filedir' CWE