Sceawere
Vulnerability Detail
CVE-2026-101039UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
FAST FAC1900R Buffer Overflow Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 10
- Creation Date
- 3h ago
- Vendor
- FAST
- Product
- FAC1900R
- Attack Type
- Stack-based Buffer Overflow
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was identified in FAST FAC1900R 20190827_2.0.2. Affected by this issue is the function copy_msg_element of the component devdiscover Service. Such manipulation leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "10.0",
"pubDate": "2026-09-28T11:16:43.600Z",
"pubdate": "2026-09-28T11:16:43.600Z",
"executiveSummary": "A critical stack-based buffer overflow vulnerability exists within the devdiscover Service of the FAST FAC1900R firmware, specifically version 20190827_2.0.2.\nThe vulnerability originates from improper bounds checking within the copy_msg_element function, allowing for remote code execution (RCE) via a malformed network packet.\nThe flaw exposes the device to unauthenticated remote attackers, posing a significant risk to system integrity, confidentiality, and availability.\nSince the vendor has remained unresponsive to disclosure efforts and functional exploit code is publicly available, the attack surface is active and requires immediate defensive attention.\nSuccessful exploitation facilitates arbitrary code execution with the privileges of the devdiscover service, potentially leading to full device compromise or persistent backdoor implantation.",
"technicalDetails": "The vulnerability resides in the copy_msg_element function within the devdiscover Service component of the FAST FAC1900R firmware version 20190827_2.0.2. The root cause is a classic stack-based buffer overflow triggered by the failure to validate the length of input data during the copy operation to a fixed-size stack buffer.\nExploitation occurs when a remote attacker sends a specifically crafted network payload to the service. The service processes the incoming message element without sufficient length verification, causing the input data to overflow the allocated stack memory space. This action overwrites critical stack metadata, including the saved return address (or stored frame pointer), allowing an attacker to redirect execution flow.\nThe attack flow follows a structured sequence: 1) The attacker initiates a network connection to the service port associated with the devdiscover service. 2) The attacker crafts a malicious packet containing a payload that exceeds the buffer size limit defined in the copy_msg_element function. 3) Upon parsing, the function copies the oversized data into the stack, overwriting adjacent memory regions. 4) The injected shellcode or ROP (Return-Oriented Programming) chain is triggered once the function attempts to return, effectively seizing control of the instruction pointer (EIP/RIP).\nGiven that the devdiscover service typically operates with elevated privileges to perform device management tasks, successful exploitation results in full system compromise. The payload behavior can range from executing arbitrary system commands to installing persistent malicious implants. As the service is network-facing, this vulnerability is exploitable remotely without requiring prior authentication, significantly lowering the barrier to entry for adversaries.\nBecause the vendor has not provided an official patch or firmware update, the system remains in a vulnerable state. The presence of publicly available exploit code suggests that automated scanning and weaponization by opportunistic attackers are likely, necessitating immediate network-level isolation or compensating controls."
}