S1 · 07/07
2025 ·
Frauscher Sensor Technology
| Company | Frauscher Sensor Technology |
| Category | rail supplier |
| Type | cyber |
| Date | 07/07 2025 |
| Time of day | not documented |
| Location | no physical site (recall / fleet-wide / aggregate record) |
| Severity | S1 (near-miss / disclosed vulnerability) |
| Scale | product line (FDS101/FDS102/FDS-SNMP101); no confirmed exploitation |
| Confidence | high |
| Verification | Cited source on file; not independently re-verified |
| Source | Frauscher PSIRT (CVE-2025-3626) |
Security researchers disclosed CVE-2025-3626 (CVSS 9.1), an OS command-injection flaw in Frauscher's FDS101/FDS102/FDS-SNMP101 diagnostic units used with its FAdC train-detection sensors, letting a high-privileged remote attacker gain full device control via a malicious config-file upload; Frauscher patched it in FDS102 v2.13.3 and no field exploitation was reported.