{"document":{"acknowledgments":[{"organization":"CERT@VDE","summary":"coordination","urls":["https://certvde.com"]}],"aggregate_severity":{"namespace":"https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale","text":"Critical"},"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en-GB","notes":[{"category":"summary","text":"Frauscher Sensortechnik FDS101, FDS-SNMP101 and FDS102 for FAdC/FAdCi R2 and all previous versions are vulnerable to OS Command Injection via malicious configuration file.\n\nCVE-2025-3626 affects FDS102 versions v2.8.0 < v2.13.3.\n\nCVE-2025-3705 affects a broader range of products and versions. Specifically, it affects:\n* FDS102 versions < v2.13.3\n* FDS101 versions <= v1.4.25\n* FDS-SNMP101 versions <= v.2.3.9\n\n**Update 1.1.0, 29.07.2025:** The summary has been updated to include a mapping between CVEs and affected products, and the remediation section has been revised to include FDS101.","title":"Summary"},{"category":"description","text":"This enables a remote or a local attacker to gain full control of the FDS101/FDS-SNMP101/FDS102 device.","title":"Impact"},{"category":"description","text":"Security-related application conditions SecRAC:\n\n* The railway operator must ensure that only authorised personnel or people in the company of\nauthorised personnel have access to the Frauscher Diagnostic System FDS101/FDS-SNMP101/FDS102. This applies for both vulnerabilities.\n\n* The recommendation is to connect the Frauscher Diagnostic System FDS102 to a network of category 2. If the Frauscher Diagnostic System FDS102 is connected to a network of category 3\n(according to EN 50159:2010), then additional protective measures must be added. This applies for CVE-2025-3626. ","title":"Mitigation"},{"category":"description","text":"Update FDS101 or FDS102 to FDS102 v2.13.3 or higher.","title":"Remediation"}],"publisher":{"category":"vendor","contact_details":"psirt@frauscher.com","name":"Frauscher Sensortechnik GmbH","namespace":"https://www.frauscher.com"},"references":[{"category":"external","summary":"Frauscher advisory overview at CERT@VDE","url":"https://certvde.com/de/advisories/vendor/frauscher/"},{"category":"external","summary":"Frauscher PSIRT","url":"https://www.frauscher.com/en/psirt"},{"category":"self","summary":"VDE-2025-030: Frauscher: FDS101, FDS-SNMP101 and FDS102 for FAdC/FAdCi are Vulnerable to OS Command Injection Vulnerability - HTML","url":"https://certvde.com/en/advisories/VDE-2025-030/"},{"category":"self","summary":"VDE-2025-030: Frauscher: FDS101, FDS-SNMP101 and FDS102 for FAdC/FAdCi are Vulnerable to OS Command Injection Vulnerability - CSAF","url":"https://frauscher.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-030.json"}],"title":"Frauscher: FDS101, FDS-SNMP101 and FDS102 for FAdC/FAdCi are Vulnerable to OS Command Injection Vulnerability","tracking":{"aliases":["VDE-2025-030"],"current_release_date":"2025-07-29T10:00:00.000Z","generator":{"date":"2025-07-29T10:30:17.379Z","engine":{"name":"Secvisogram","version":"2.5.31"}},"id":"VDE-2025-030","initial_release_date":"2025-07-07T10:00:00.000Z","revision_history":[{"date":"2025-07-07T10:00:00.000Z","number":"1.0.0","summary":"Initial revision"},{"date":"2025-07-29T10:00:00.000Z","number":"1.1.0","summary":"The summary has been updated to include a mapping between CVEs and affected products, and the remediation section has been revised to include FDS101."}],"status":"final","version":"1.1.0"}},"product_tree":{"branches":[{"branches":[{"branches":[{"branches":[{"branches":[{"category":"product_version","name":"v2.13.3","product":{"name":"FDS102 v2.13.3","product_id":"CSAFID-52001"}},{"category":"product_version_range","name":">=v2.8.0<v2.13.2","product":{"name":"FDS102 >=v2.8.0<v2.13.3","product_id":"CSAFID-51001"}},{"category":"product_version_range","name":"<v2.13.3","product":{"name":"FDS102 <v2.13.3","product_id":"CSAFID-51002"}}],"category":"product_name","name":"102"},{"branches":[{"category":"product_version_range","name":"<=v1.4.25","product":{"name":"FDS101 <=v1.4.25","product_id":"CSAFID-51003"}}],"category":"product_name","name":"101"},{"branches":[{"category":"product_version_range","name":"<=v.2.3.9","product":{"name":"FDS-SNMP101 <=v.2.3.9","product_id":"CSAFID-51004"}}],"category":"product_name","name":"SNMP101"}],"category":"product_family","name":"FDS"}],"category":"product_family","name":"Software"}],"category":"vendor","name":"Frauscher"}],"product_groups":[{"group_id":"CSAFGID-0001","product_ids":["CSAFID-51001","CSAFID-51002","CSAFID-51003","CSAFID-51004"],"summary":"Affected Products."}]},"vulnerabilities":[{"cve":"CVE-2025-3626","cwe":{"id":"CWE-78","name":"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"},"notes":[{"category":"description","text":"A remote attacker with administrator account can gain full control of the device due to improper neutralization of special elements used in an OS Command ('OS Command Injection') while uploading a config file via webUI.","title":"Description"}],"product_status":{"fixed":["CSAFID-52001"],"known_affected":["CSAFID-51001"]},"remediations":[{"category":"vendor_fix","details":"Update to FDS102 v2.13.3","product_ids":["CSAFID-51001"]},{"category":"mitigation","details":"Security-related application conditions SecRAC:\n\n* The railway operator must ensure that only authorised personnel or people in the company of\nauthorised personnel have access to the Frauscher Diagnostic System FDS102.\n\n* The recommendation is to connect the Frauscher Diagnostic System FDS102 to a network of category 2. If the Frauscher Diagnostic System FDS102 is connected to a network of category 3\n(according to EN 50159:2010), then additional protective measures must be added.","product_ids":["CSAFID-51001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","environmentalScore":9.1,"environmentalSeverity":"CRITICAL","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"CHANGED","temporalScore":9.1,"temporalSeverity":"CRITICAL","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"products":["CSAFID-51001"]}],"title":"CVE-2025-3626"},{"cve":"CVE-2025-3705","cwe":{"id":"CWE-78","name":"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"},"notes":[{"category":"description","text":"A physical attacker with no privileges can gain full control of the affected device due to improper neutralization of special elements used in an OS Command ('OS Command Injection') when loading a config file from a USB drive.","title":"Description"}],"product_status":{"fixed":["CSAFID-52001"],"known_affected":["CSAFID-51002","CSAFID-51003","CSAFID-51004"]},"remediations":[{"category":"vendor_fix","details":"Update to FDS102 v2.13.3","product_ids":["CSAFID-51002","CSAFID-51003"]},{"category":"mitigation","details":"Security-related application conditions SecRAC:\n\n* The railway operator must ensure that only authorised personnel or people in the company of\nauthorised personnel have access to the Frauscher Diagnostic System FDS101/FDS-SNMP101/FDS102.","product_ids":["CSAFID-51002","CSAFID-51003","CSAFID-51004"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"PHYSICAL","availabilityImpact":"HIGH","baseScore":6.8,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","environmentalScore":6.8,"environmentalSeverity":"MEDIUM","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":6.8,"temporalSeverity":"MEDIUM","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["CSAFID-51002","CSAFID-51003","CSAFID-51004"]}],"title":"CVE-2025-3705"}]}