Security Advisory

CVE-2026-14952

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-20 08:19:46
Last updated 2026-08-20 15:26:26
Assigner CERTVDE
CVSS score 8.7
State PUBLISHED

Description

An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users.