<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:fast:fac1900r:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3afastfac1900r/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 28 Sep 2026 12:14:31 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3afastfac1900r/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Critical Buffer Overflow in FAST FAC1900R devdiscover Service</title><link>https://feed.craftedsignal.io/briefs/2026-09-fast-fac1900r-overflow/</link><pubDate>Mon, 28 Sep 2026 12:14:31 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-fast-fac1900r-overflow/</guid><description>A critical stack-based buffer overflow in the devdiscover service of the FAST FAC1900R network device allows remote code execution due to improper handling in the copy_msg_element function.</description><content:encoded><![CDATA[<p>A critical security vulnerability (CVE-2026-101039) has been identified in the FAST FAC1900R device, specifically firmware version 20190827_2.0.2. The vulnerability exists within the copy_msg_element function of the devdiscover service, which is responsible for network device discovery. This flaw allows a remote, unauthenticated attacker to trigger a stack-based buffer overflow by sending specially crafted packets to the affected service. Successful exploitation of this vulnerability can lead to arbitrary code execution on the device or cause a denial of service (DoS) condition. As the vendor has not responded to disclosure efforts and public exploit code is available, this vulnerability poses a significant risk to organizations utilizing this hardware in their network infrastructure.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows remote attackers to compromise the integrity and availability of FAST FAC1900R network devices. Attackers can gain remote code execution to establish persistence, move laterally within the network, or disrupt critical network services managed by the device. As of this report, no vendor patch is available.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the isolation of all FAST FAC1900R devices from the public internet. Ensure these devices are positioned behind strict firewall rules that restrict access to the devdiscover service ports to trusted management subnets only. Given the unavailability of a vendor patch, decommissioning these legacy devices is the recommended path for risk mitigation in sensitive environments.</p>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>