RobotRisk Autonomous Systems Incident & Risk Register
RobotRisk / Frauscher Sensor Technology / 2025-07-07

Critical command-injection vulnerability disclosed in Frauscher train-detection diagnostic system

S1 · 07/07
2025 · Frauscher Sensor Technology

Record

CompanyFrauscher Sensor Technology
Categoryrail supplier
Typecyber
Date07/07
2025
Time of daynot documented
Locationno physical site (recall / fleet-wide / aggregate record)
SeverityS1 (near-miss / disclosed vulnerability)
Scaleproduct line (FDS101/FDS102/FDS-SNMP101); no confirmed exploitation
Confidencehigh
VerificationCited source on file; not independently re-verified
SourceFrauscher PSIRT (CVE-2025-3626)

What happened

Security researchers disclosed CVE-2025-3626 (CVSS 9.1), an OS command-injection flaw in Frauscher's FDS101/FDS102/FDS-SNMP101 diagnostic units used with its FAdC train-detection sensors, letting a high-privileged remote attacker gain full device control via a malicious config-file upload; Frauscher patched it in FDS102 v2.13.3 and no field exploitation was reported.

Frauscher Sensor Technology record context

Frauscher Sensor Technology vs rail supplier alternatives

rail supplier context

rail supplier: entries by year

122015 S4: 11152017 S2: 12017 S4: 12172020 S5: 11202021 S3: 12021 S5: 12212023 S2: 11232024 S4: 11242025 S1: 11252026 S2: 12026 S3: 1226
S1S2S3S4S5

rail supplier: failure modes

rail supplier: most entries

cyber context

cyber: by category

cyber: by year

cyber: severity profile

Other Frauscher Sensor Technology entries

Also from Critical Systems Analysis: CSA - functional safety engineering · Company directory · FSTalent - functional safety jobs