Impact
This vulnerability originates in the parse_advertisement_frame function of the devdiscover Service in FAST FAC1200R firmware 5.0_20201119_1.0.2. An attacker can supply a crafted frame that causes a stack-based buffer overflow, allowing arbitrary code execution or denial of service on the device. The flaw is a classic buffer overflow (CWE‑119) combined with improper stack guard handling (CWE‑121). The vendor has not released a fix and the exploit has been made public.
Affected Systems
The affected product is the FAST FAC1200R device. No additional vendor or product prefixes are listed beyond FAST:FAC1200R, and the specific firmware snapshot 5.0_20201119_1.0.2 is identified as vulnerable.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity, and the EPSS score is not available but the exploit is publicly disclosed, making exploitation likely in environments where the service is reachable. There is no listing in the CISA KEV catalog, but the remote nature of the attack and lack of vendor response increase risk. Without a patch, the vulnerability can be exercised by any attacker who can reach the devdiscover Service, typically via the network interface the device advertises. The attack likely requires only the ability to transmit a malformed frame to the service, which may be possible over local or remote networks depending on the device exposure.
OpenCVE Enrichment