<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:o:fast:fac1200r_firmware:5.0_20201119_1.0.2:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3ofastfac1200r_firmware5.0_20201119_1.0.2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 28 Sep 2026 12:14:21 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3ofastfac1200r_firmware5.0_20201119_1.0.2/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Stack-Based Buffer Overflow in FAST FAC1200R devdiscover Service</title><link>https://feed.craftedsignal.io/briefs/2026-09-fast-fac1200r-overflow/</link><pubDate>Mon, 28 Sep 2026 12:14:21 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-fast-fac1200r-overflow/</guid><description>A critical stack-based buffer overflow vulnerability in the devdiscover service of FAST FAC1200R routers allows unauthenticated remote attackers to achieve code execution via malformed advertisement frames.</description><content:encoded><![CDATA[<p>A critical stack-based buffer overflow vulnerability, identified as CVE-2026-101037, has been disclosed in the FAST FAC1200R router, specifically within the <code>parse_advertisement_frame</code> function of the <code>devdiscover</code> service. This vulnerability, affecting version 5.0_20201119_1.0.2, allows unauthenticated remote attackers to trigger a crash or potentially execute arbitrary code by sending a specially crafted advertisement frame to the device. Public exploit code for this vulnerability is currently available, significantly increasing the risk of exploitation. The vendor has reportedly failed to respond to disclosure attempts, leaving affected systems without a patch. Defenders should prioritize identifying exposed router interfaces and restricting access to the <code>devdiscover</code> service management ports to prevent remote exploitation.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows an unauthenticated, remote attacker to gain control over the affected network device. Given that the device is a router, this provides a foothold for further lateral movement into the internal network, traffic interception, or the establishment of persistent backdoors. As the vendor has not released a patch, affected organizations face a sustained risk of remote code execution.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Perform an immediate audit to identify all FAST FAC1200R devices exposed to the internet.</li>
<li>Implement network-level access controls to restrict access to management services on these devices to authorized management IP addresses only.</li>
<li>Monitor network traffic for anomalous advertisement frames directed at router management interfaces.</li>
<li>Given the lack of a vendor patch, evaluate replacing affected hardware with models currently receiving active security support.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>remote-code-execution</category><category>buffer-overflow</category><category>network-infrastructure</category></item></channel></rss>