<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>FAC1203R Gigabit Edition (2.0.4) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/fac1203r-gigabit-edition-2.0.4/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 23 Sep 2026 04:41:17 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/fac1203r-gigabit-edition-2.0.4/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stack-Based Buffer Overflow in Fast FAC1203R Gigabit Edition</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-96257/</link><pubDate>Wed, 23 Sep 2026 04:41:17 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-96257/</guid><description>A critical stack-based buffer overflow vulnerability in the Device Discovery Service of Fast FAC1203R firmware 2.0.4 allows for unauthenticated remote code execution.</description><content:encoded><![CDATA[<p>A critical security vulnerability (CVE-2026-96257) has been identified in the Fast FAC1203R Gigabit Edition firmware version 2.0.4. The vulnerability originates in the copy_msg_element function within the Device Discovery Service. Due to improper input validation, an attacker can trigger a stack-based buffer overflow by sending a specially crafted packet to the device. Because the service is exposed and reachable remotely, this flaw allows for unauthenticated remote code execution with the privileges of the service. Publicly available exploit code exists, increasing the risk of active exploitation. The vendor has not responded to disclosure attempts, and no security patches are currently available.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in full system compromise, allowing an attacker to execute arbitrary code with elevated privileges on the network device. This facilitates deeper lateral movement into the local network, traffic interception, and potential persistence within the infrastructure. This vulnerability is rated with a CVSS v3.1 base score of 10.0, indicating the highest level of severity.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Restrict network access to the Device Discovery Service on all Fast FAC1203R units to trusted management segments only.</li>
<li>Implement network-level egress and ingress filtering to identify anomalous packet structures targeting common device discovery ports.</li>
<li>Monitor device logs for signs of service crashes or unauthorized configuration changes, which may indicate attempted exploitation of CVE-2026-96257.</li>
<li>Isolate vulnerable hardware from the public internet until a firmware update is provided by the vendor.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">threat</category><category>cve</category><category>remote-code-execution</category><category>buffer-overflow</category></item></channel></rss>