Sceawere

Vulnerability Detail

CVE-2026-101354UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

FAST FAC1203R Buffer Overflow

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.6
Creation Date
5h ago
Vendor
FAST
Product
FAC1203R
Attack Type
Stack-based Buffer Overflow
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affected element is the function _tWlanTask of the component MmtAtePrase Parser. Performing a manipulation results in stack-based buffer overflow. The attacker must have access to the local network to execute the attack. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.6",
  "pubDate": "2026-09-29T02:16:53.230Z",
  "pubdate": "2026-09-29T02:16:53.230Z",
  "executiveSummary": "A critical stack-based buffer overflow vulnerability exists in the MmtAtePrase Parser component of the FAST FAC1203R router, specifically within the _tWlanTask function.\nThe vulnerability allows for memory corruption when the device processes maliciously crafted input, potentially leading to arbitrary code execution or a denial-of-service condition.\nThe vulnerability affects firmware version 20200116_2.0.4. Successful exploitation requires an attacker to have access to the local network to transmit the malicious payload.\nThis vulnerability is classified as high-risk due to the availability of public exploit material and the lack of vendor response or remediation patches.\nThe absence of vendor communication increases the risk of long-term exposure, as no official firmware updates are available to address the underlying flaw.",
  "technicalDetails": "The vulnerability is a classic stack-based buffer overflow located within the _tWlanTask function, which is a component of the MmtAtePrase Parser module in the FAST FAC1203R router (firmware 20200116_2.0.4).\nThe root cause of this vulnerability lies in improper bounds checking of user-supplied data before copying it into a fixed-size buffer allocated on the task's stack frame. When the MmtAtePrase Parser handles specifically malformed data during the execution of _tWlanTask, the input exceeds the buffer's capacity, leading to an overwrite of adjacent stack memory.\nBecause the overflow occurs on the stack, an attacker can manipulate the saved return address or overwrite critical function pointers to hijack the program's execution flow. By carefully crafting the overflow payload, an attacker can redirect the instruction pointer to arbitrary memory locations, such as malicious shellcode injected as part of the initial buffer, or employ return-oriented programming (ROP) chains to bypass security mitigations if present.\nThe attack flow requires the attacker to be positioned on the local network segment. The adversary sends a specially crafted packet or network stream intended for the MmtAtePrase Parser. As the parser routines process this traffic, the _tWlanTask function fails to validate the length of the input data against the destination stack buffer. Once the copy operation concludes, the stack frame is corrupted, leading to anomalous device behavior.\nUpon successful exploitation, the attacker can achieve remote code execution (RCE) with the privileges of the process running _tWlanTask. Given the function's nature, this likely results in full compromise of the router's operating system, potentially allowing the attacker to persist, intercept network traffic, or pivot further into the internal network environment. Given that the exploit code has been publicly released, the barrier to entry for potential attackers is significantly reduced, necessitating immediate protective measures for all deployments of this firmware version."
}
CVE-2026-101354: FAST FAC1203R Buffer Overflow (CRITICAL Severity, CVSS: 9.6) | Sceawere