RobotRisk Autonomous Systems Incident & Risk Register
RobotRiskFrauscher Sensor Technology › 07 Jul 2025

Critical command-injection vulnerability disclosed in Frauscher train-detection diagnostic system

S1 · 07 Jul 2025 · Frauscher Sensor Technology

Record

CompanyFrauscher Sensor Technology
IndustryRail suppliers
Type(s)cyber
Date07 Jul 2025 (day precision)
Time of daynot documented
Locationno physical site (recall / fleet-wide / aggregate record)
Severity (near-miss / disclosed vulnerability)
Scaleproduct line (FDS101/FDS102/FDS-SNMP101); no confirmed exploitation
Confidencehigh
Verified flagCited source on file; not independently re-verified

Summary

Security researchers disclosed CVE-2025-3626 (CVSS 9.1), an OS command-injection flaw in Frauscher's FDS101/FDS102/FDS-SNMP101 diagnostic units used with its FAdC train-detection sensors, letting a high-privileged remote attacker gain full device control via a malicious config-file upload; Frauscher patched it in FDS102 v2.13.3 and no field exploitation was reported.

Primary source

Frauscher PSIRT (CVE-2025-3626)

Publisher: Frauscher PSIRT (CVE-2025-3626) · Retrieved: 2026-09-16

Supporting source rows (1)
DateSupporting source rowPublisherLink
07 Jul 2025 Critical command-injection vulnerability disclosed in Frauscher train-detection diagnostic system Frauscher PSIRT (CVE-2025-3626) Frauscher PSIRT

Rail suppliers context

cyber context

Frauscher Sensor Technology industry position

Related incidents

No related unique incidents are on file.

Other Frauscher Sensor Technology entries

Report a correction

Open a prefilled GitHub issue

Also from Critical Systems Analysis: CSA - functional safety engineering · Company directory · FSTalent - functional safety jobs