Sceawere

Vulnerability Detail

CVE-2026-101037UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

FAST FAC1200R Stack Buffer Overflow

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.9
Creation Date
4h ago
Vendor
FAST
Product
FAC1200R
Attack Type
Stack-based Buffer Overflow
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was found in FAST FAC1200R 5.0_20201119_1.0.2. Affected is the function parse_advertisement_frame of the component devdiscover Service. The manipulation results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.9",
  "pubDate": "2026-09-28T10:16:42.793Z",
  "pubdate": "2026-09-28T10:16:42.793Z",
  "executiveSummary": "A critical stack-based buffer overflow vulnerability has been identified in the devdiscover service of the FAST FAC1200R router, specifically within the parse_advertisement_frame function.\nThe vulnerability allows for remote exploitation, potentially enabling unauthenticated attackers to execute arbitrary code or cause a denial-of-service condition on the affected device.\nThe failure of the vendor to respond to disclosure notifications increases the risk posture for organizations deploying this hardware, as no official firmware patch is available to remediate the flaw.\nAttackers can leverage publicly available exploit code to facilitate remote compromise, making the device a significant vector for network-level exploitation.\nThe flaw stems from insufficient input validation during the parsing of advertisement frames, leading to memory corruption.",
  "technicalDetails": "The vulnerability is rooted in a stack-based buffer overflow condition present within the parse_advertisement_frame function of the devdiscover service.\nThe root cause is identified as improper bounds checking when processing incoming advertisement frame data. The function fails to validate the size of the input payload against the allocated stack buffer, allowing an attacker to supply a crafted packet that exceeds the buffer's capacity.\nWhen the devdiscover service receives a maliciously formed advertisement frame, the excessive data overwrites the stack memory, including critical control structures such as the return address (saved link register or instruction pointer, depending on the architecture).\nAn attacker can exploit this by crafting a specific payload containing shellcode or a ROP (Return-Oriented Programming) chain. By precisely controlling the overflow, the attacker can hijack the execution flow of the devdiscover process.\nThe attack flow proceeds as follows: 1) The attacker sends a malformed advertisement frame packet over the network to the target device. 2) The devdiscover service receives the packet and triggers the vulnerable parse_advertisement_frame function. 3) The function performs an unsafe memory copy (e.g., using functions like memcpy, strcpy, or manual loop-based copies without length checks) into a fixed-size stack buffer. 4) The stack buffer overflows, overwriting the saved return address. 5) Upon function completion, the processor returns execution to the address dictated by the attacker's payload, facilitating arbitrary code execution.\nGiven that the devdiscover service typically runs with elevated privileges on embedded networking hardware, successful exploitation grants the attacker extensive control over the router's operating environment. Post-exploitation impact includes persistent compromise, lateral movement within the network, traffic interception, and potential full device takeover. The exploit is remote and does not require prior authentication, significantly lowering the barrier for exploitation by malicious actors.\nAffected Version: FAST FAC1200R 5.0_20201119_1.0.2."
}
CVE-2026-101037: FAST FAC1200R Stack Buffer Overflow (CRITICAL Severity, CVSS: 9.9) | Sceawere