Skip to content
Threat Feed
critical advisory

Insufficient Session Expiration in Frauscher Sensortechnik FDS 102

CVE-2026-14950 is an insufficient session expiration vulnerability in Frauscher Sensortechnik FDS 102 that allows an attacker with a valid session identifier to maintain access beyond the intended expiration time.

CVE search metadata

CVE search record: CVE-2026-14950. Severity: critical. CVSS: 9.8. KEV: no. Product: FDS 102 (2.1.0 to 2.13.3), FDS 102 (2.8.0-2.13.3), FDS 102, FDS 102 (2.13.0 - 2.13.3). Brief: Insufficient Session Expiration in Frauscher Sensortechnik FDS 102. Brief link: https://feed.craftedsignal.io/briefs/2026-08-fds-session-expiration/

What's new

  • 1. added detection rule: Detect CVE-2026-14952 Exploitation - Unauthorized Access to FDS Backup Aug 20, 11:12 via nvd
  • 2. added detection rule: Detect Suspicious Diagnostic Log Archive Download Aug 20, 11:12 via nvd
  • 3. added coverage for FDS 102 Aug 20, 11:12 via nvd
  • 4. added detection rule: Detect CVE-2026-14946 Exploitation - Unauthorized File Upload and Access Aug 20, 11:11 via nvd

CVE-2026-14950 identifies an insufficient session expiration flaw (CWE-613) within the web interface of the Frauscher Sensortechnik FDS 102 system, affecting versions 2.1.0 through 2.13.3. This vulnerability enables an unauthenticated attacker who has obtained a valid session identifier - potentially through interception, theft, or by leveraging an unattended machine - to continue using the session indefinitely, even after the system's expiration policy should have terminated it. This persistence mechanism allows unauthorized users to maintain an active, authenticated state, effectively bypassing standard session timeout security controls. Defenders should prioritize patching affected FDS 102 units and implement strict monitoring for anomalous session activity or unauthorized session token reuse.

Impact

The vulnerability carries a CVSS v3.1 score of 9.8 (Critical), indicating high risk for unauthorized access and control over the affected FDS 102 interface. If exploited, an attacker gains persistent access to the management environment, potentially leading to unauthorized monitoring or configuration changes of sensitive industrial sensor systems. The vulnerability affects a critical component of industrial infrastructure management, and failure to apply available patches leaves systems open to prolonged unauthorized access.

Recommendation

  • Apply the security update provided by Frauscher Sensortechnik to all FDS 102 instances running version 2.13.3 or earlier to remediate CVE-2026-14950.
  • Monitor web application logs for session tokens that persist beyond expected operational windows or show abnormal temporal patterns.
  • Enforce strict session management policies, including idle timeouts and secure transport (HTTPS) to mitigate the risk of session identifier interception.

Immediate actions

Upgrade Frauscher Sensortechnik FDS 102 to the patched version.

IT Operations 72h

Detection coverage 3

Detect CVE-2026-14946 Exploitation - Unauthorized File Upload and Access

high

Detects exploitation of CVE-2026-14946 by monitoring for HTTP requests to .php files within the /uploads/ directory.

sigma tactics: initial_access techniques: T1505.003 sources: webserver

Detect Suspicious Diagnostic Log Archive Download

high

Detects potential exploitation of CVE-2026-14948 by monitoring for access to log archive endpoints, specifically focusing on non-admin user requests.

sigma tactics: initial_access techniques: T1185, T1552.002 sources: webserver

Detect CVE-2026-14952 Exploitation - Unauthorized Access to FDS Backup

high

Detects attempts to download sensitive files directly from the FDS 102 web server without authentication or via unauthorized paths.

sigma tactics: discovery, initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →