Skip to content
Threat Feed
critical advisory

Remote Stack-Based Buffer Overflow in FAST FAC1200R devdiscover Service

A critical stack-based buffer overflow vulnerability in the devdiscover service of FAST FAC1200R routers allows unauthenticated remote attackers to achieve code execution via malformed advertisement frames.

CVE search metadata

CVE search record: CVE-2026-101037. Severity: critical. CVSS: 9.9. KEV: no. Product: FAC1200R (5.0_20201119_1.0.2). Brief: Remote Stack-Based Buffer Overflow in FAST FAC1200R devdiscover Service. Brief link: https://feed.craftedsignal.io/briefs/2026-09-fast-fac1200r-overflow/

A critical stack-based buffer overflow vulnerability, identified as CVE-2026-101037, has been disclosed in the FAST FAC1200R router, specifically within the parse_advertisement_frame function of the devdiscover service. This vulnerability, affecting version 5.0_20201119_1.0.2, allows unauthenticated remote attackers to trigger a crash or potentially execute arbitrary code by sending a specially crafted advertisement frame to the device. Public exploit code for this vulnerability is currently available, significantly increasing the risk of exploitation. The vendor has reportedly failed to respond to disclosure attempts, leaving affected systems without a patch. Defenders should prioritize identifying exposed router interfaces and restricting access to the devdiscover service management ports to prevent remote exploitation.

Impact

Successful exploitation of this vulnerability allows an unauthenticated, remote attacker to gain control over the affected network device. Given that the device is a router, this provides a foothold for further lateral movement into the internal network, traffic interception, or the establishment of persistent backdoors. As the vendor has not released a patch, affected organizations face a sustained risk of remote code execution.

Recommendation

  • Perform an immediate audit to identify all FAST FAC1200R devices exposed to the internet.
  • Implement network-level access controls to restrict access to management services on these devices to authorized management IP addresses only.
  • Monitor network traffic for anomalous advertisement frames directed at router management interfaces.
  • Given the lack of a vendor patch, evaluate replacing affected hardware with models currently receiving active security support.

Immediate actions

Isolate affected FAST FAC1200R devices from public network exposure.

IT Operations 24h

Mitigations

Restrict management interface access via firewall or ACL.

immediate IT Operations

CVE-2026-101037