Vulnerability Description
An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-14952?
CVE-2026-14952 is a vulnerability with a CVSS score of 7.5 (HIGH). An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without...
How severe is CVE-2026-14952?
CVE-2026-14952 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-14952?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.