Sceawere
Vulnerability Detail
CVE-2026-101038UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
FAST FAC1200R Stack Buffer Overflow
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.9
- Creation Date
- 3h ago
- Vendor
- FAST
- Product
- FAC1200R
- Attack Type
- Stack-based Buffer Overflow
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was determined in FAST FAC1200R 5.0_20201119_1.0.2. Affected by this vulnerability is the function MmtAtePrase of the component MmtAtePrase Parser. This manipulation causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.9",
"pubDate": "2026-09-28T11:16:43.423Z",
"pubdate": "2026-09-28T11:16:43.423Z",
"executiveSummary": "A critical stack-based buffer overflow vulnerability exists in the FAST FAC1200R router, specifically within the MmtAtePrase component.\nThe vulnerability resides in the MmtAtePrase function, which improperly handles input during parsing operations.\nThis flaw allows a remote, unauthenticated attacker to trigger a memory corruption event, potentially leading to arbitrary code execution or a denial-of-service condition.\nThe vulnerability is currently publicly disclosed, and given the lack of vendor response or available patches, the risk to affected systems is significant.\nSuccessful exploitation allows an attacker to overwrite the stack, enabling control over the execution flow of the device.\nExploitation requires network connectivity to the vulnerable component, making this a remote attack vector.",
"technicalDetails": "The vulnerability is classified as a stack-based buffer overflow affecting the MmtAtePrase function within the MmtAtePrase Parser component of the FAST FAC1200R router (version 5.0_20201119_1.0.2).\nThe root cause is a failure to implement proper bounds checking when parsing input data processed by the MmtAtePrase function. By supplying a maliciously crafted payload that exceeds the allocated buffer size on the stack, an attacker can overwrite adjacent memory, including critical data such as the saved frame pointer and the return address.\nThe exploitation flow begins with the attacker sending a specifically engineered packet or request to the device's management interface or relevant listening service that invokes the MmtAtePrase parser. Because the function does not validate the length of the incoming data, the provided input is copied into a fixed-size stack buffer via an unsafe operation (such as strcpy, sprintf, or an unconstrained loop).\nUpon overflowing the buffer, the attacker can overwrite the return address stored on the stack. When the MmtAtePrase function reaches its return instruction, the execution flow is redirected to an attacker-controlled memory address. In a typical exploitation scenario, this involves redirecting execution to shellcode injected within the overflow payload or utilizing Return-Oriented Programming (ROP) chains to bypass security mitigations like Data Execution Prevention (DEP), if enabled.\nThis vulnerability is remotely exploitable, as it does not require prior authentication. The impact of successful exploitation includes full system compromise, as the process running the MmtAtePrase parser often operates with elevated privileges, granting the attacker control over the underlying firmware environment. Furthermore, if the payload is malformed or intentionally crashes the process, it will result in a denial-of-service, rendering the router non-functional until a manual reboot occurs.\nThere are no indications of built-in Address Space Layout Randomization (ASLR) or stack canaries being robustly implemented in this firmware version to prevent such overflows, significantly lowering the complexity for an attacker to gain successful code execution."
}