<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>FAC1203R (20200116_2.0.4) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/fac1203r-20200116_2.0.4/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 02:23:43 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/fac1203r-20200116_2.0.4/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stack-Based Buffer Overflow in FAST FAC1203R MmtAtePrase Parser</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-101354/</link><pubDate>Tue, 29 Sep 2026 02:23:43 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-101354/</guid><description>A stack-based buffer overflow vulnerability in the _tWlanTask function of the FAST FAC1203R router allows remote code execution via network-based manipulation.</description><content:encoded><![CDATA[<p>A critical stack-based buffer overflow vulnerability, identified as CVE-2026-101354, exists in the MmtAtePrase parser component of the FAST FAC1203R network device, specifically within the _tWlanTask function. The vulnerability is triggered by sending specially crafted network traffic to the device. An attacker must have access to the local network to reach the vulnerable function. Public exploit code is available for this vulnerability, and the vendor has not provided a patch or acknowledged the disclosure. This defect poses a significant risk to the integrity and availability of impacted devices, as successful exploitation may result in unauthorized code execution.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows an unauthenticated attacker on the local network to trigger a stack-based buffer overflow in the device firmware. This can lead to device crashes or the execution of arbitrary code with the privileges of the _tWlanTask, effectively granting the attacker full control over the affected FAC1203R unit. Given the public availability of exploit code, the risk of exploitation is high.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Since no vendor patch is available, prioritize isolating the FAST FAC1203R devices from the local network to restrict unauthorized access to the vulnerable _tWlanTask function.</li>
<li>Implement strict access control lists (ACLs) on network segments where these devices are deployed to prevent unauthorized traffic from reaching the device management or wireless interfaces.</li>
<li>Monitor network traffic for unusual patterns directed at the FAC1203R device, particularly traffic that could target the parser component, until the vendor addresses the vulnerability.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>remote-code-execution</category><category>networking</category></item></channel></rss>