CVE-2026-14950 PUBLISHED

Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Insufficient Session Expiration due to flawed session expiration logic

Assigner: CERTVDE
Reserved: 07.07.2026 Published: 20.08.2026 Updated: 20.08.2026

An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. This increases the risk associated with stolen, leaked, shared, or unattended sessions and may enable unauthorized continued access to the FDS web interface.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.2

Product Status

Vendor Frauscher Sensortechnik
Product FDS 102
Versions Default: unaffected
  • affected from 2.1.0 to 2.13.3 (incl.)

References

Problem Types

  • CWE-613 Insufficient Session Expiration CWE