Frauscher is a niche industrial railway-systems vendor whose vulnerability profile centers on its Diagnostic System product line, a narrowly deployed but critical component in rail infrastructure. The vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through input-handling weakness classes including code injection, path traversal, SQL injection, and unrestricted file upload—patterns characteristic of web-facing diagnostic interfaces that process untrusted operator input in safety-critical environments. Defenders managing railway automation and monitoring systems should treat Frauscher advisories with high priority; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Frauscher over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3575CRITICAL Frauscher Sensortechnik GmbH FDS102 for FAdC R2 and FAdCi R2 v2.8.0 to v2.9.1 are vulnerable to malicious code upload without authentication by using the configuration upload funct | Nov 2, 2022 | 9.8 | 31 | NO | NO |
CVE-2023-4291CRITICAL Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are vulnerable to a remote code execution (RCE) vulnerability via manipulated parameters of the | Sep 21, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-5500HIGH This vulnerability allows an remote attacker with low privileges to misuse Improper Control of Generation of Code ('Code Injection') to gain full control of the affected device. | Dec 11, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-4152HIGH Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are vulnerable to a path traversal vulnerability of the web interface by a crafted URL without | Sep 21, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-2880HIGH Frauscher Sensortechnik GmbH FDS001 for FAdC/FAdCi v1.3.3 and all previous versions are vulnerable to a path traversal vulnerability of the web interface by a crafted URL without a | Jul 5, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-4292MEDIUM Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are vulnerable to a SQL injection vulnerability via manipulated parameters of the web interface | Sep 21, 2023 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Frauscher.
Media articles that mention a CVE ID that affects a product developed by Frauscher — matched by CVE ID, not by vendor name.