{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3afastfac1900r/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:fast:fac1900r:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2026-101039"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FAC1900R (20190827_2.0.2)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["FAST"],"content_html":"\u003cp\u003eA critical security vulnerability (CVE-2026-101039) has been identified in the FAST FAC1900R device, specifically firmware version 20190827_2.0.2. The vulnerability exists within the copy_msg_element function of the devdiscover service, which is responsible for network device discovery. This flaw allows a remote, unauthenticated attacker to trigger a stack-based buffer overflow by sending specially crafted packets to the affected service. Successful exploitation of this vulnerability can lead to arbitrary code execution on the device or cause a denial of service (DoS) condition. As the vendor has not responded to disclosure efforts and public exploit code is available, this vulnerability poses a significant risk to organizations utilizing this hardware in their network infrastructure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote attackers to compromise the integrity and availability of FAST FAC1900R network devices. Attackers can gain remote code execution to establish persistence, move laterally within the network, or disrupt critical network services managed by the device. As of this report, no vendor patch is available.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the isolation of all FAST FAC1900R devices from the public internet. Ensure these devices are positioned behind strict firewall rules that restrict access to the devdiscover service ports to trusted management subnets only. Given the unavailability of a vendor patch, decommissioning these legacy devices is the recommended path for risk mitigation in sensitive environments.\u003c/p\u003e\n","date_modified":"2026-09-28T12:14:31Z","date_published":"2026-09-28T12:14:31Z","id":"https://feed.craftedsignal.io/briefs/2026-09-fast-fac1900r-overflow/","summary":"A critical stack-based buffer overflow in the devdiscover service of the FAST FAC1900R network device allows remote code execution due to improper handling in the copy_msg_element function.","title":"Critical Buffer Overflow in FAST FAC1900R devdiscover Service","url":"https://feed.craftedsignal.io/briefs/2026-09-fast-fac1900r-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:fast:fac1900r:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}