{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/fac1200r-5.0_20201119_1.0.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:fast:fac1200r_firmware:5.0_20201119_1.0.2:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-101037"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FAC1200R (5.0_20201119_1.0.2)"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","buffer-overflow","network-infrastructure"],"_cs_type":"advisory","_cs_vendors":["FAST"],"content_html":"\u003cp\u003eA critical stack-based buffer overflow vulnerability, identified as CVE-2026-101037, has been disclosed in the FAST FAC1200R router, specifically within the \u003ccode\u003eparse_advertisement_frame\u003c/code\u003e function of the \u003ccode\u003edevdiscover\u003c/code\u003e service. This vulnerability, affecting version 5.0_20201119_1.0.2, allows unauthenticated remote attackers to trigger a crash or potentially execute arbitrary code by sending a specially crafted advertisement frame to the device. Public exploit code for this vulnerability is currently available, significantly increasing the risk of exploitation. The vendor has reportedly failed to respond to disclosure attempts, leaving affected systems without a patch. Defenders should prioritize identifying exposed router interfaces and restricting access to the \u003ccode\u003edevdiscover\u003c/code\u003e service management ports to prevent remote exploitation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an unauthenticated, remote attacker to gain control over the affected network device. Given that the device is a router, this provides a foothold for further lateral movement into the internal network, traffic interception, or the establishment of persistent backdoors. As the vendor has not released a patch, affected organizations face a sustained risk of remote code execution.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePerform an immediate audit to identify all FAST FAC1200R devices exposed to the internet.\u003c/li\u003e\n\u003cli\u003eImplement network-level access controls to restrict access to management services on these devices to authorized management IP addresses only.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic for anomalous advertisement frames directed at router management interfaces.\u003c/li\u003e\n\u003cli\u003eGiven the lack of a vendor patch, evaluate replacing affected hardware with models currently receiving active security support.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-28T12:14:21Z","date_published":"2026-09-28T12:14:21Z","id":"https://feed.craftedsignal.io/briefs/2026-09-fast-fac1200r-overflow/","summary":"A critical stack-based buffer overflow vulnerability in the devdiscover service of FAST FAC1200R routers allows unauthenticated remote attackers to achieve code execution via malformed advertisement frames.","title":"Remote Stack-Based Buffer Overflow in FAST FAC1200R devdiscover Service","url":"https://feed.craftedsignal.io/briefs/2026-09-fast-fac1200r-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - FAC1200R (5.0_20201119_1.0.2)","version":"https://jsonfeed.org/version/1.1"}