Description
A vulnerability was determined in FAST FAC1200R 5.0_20201119_1.0.2. Affected by this vulnerability is the function MmtAtePrase of the component MmtAtePrase Parser. This manipulation causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The FAST FAC1200R router is vulnerable to a stack-based buffer overflow in the MmtAtePrase parser, which can be triggered remotely and may allow an attacker to execute arbitrary code on the device. The flaw corresponds to CWE-119 and CWE-121 and can compromise the confidentiality, integrity, and availability of the affected system.

Affected Systems

FAST FAC1200R routers running firmware version 5.0_20201119_1.0.2 are impacted. No other versions are listed as affected.

Risk and Exploitability

The CVSS score of 9.4 indicates a critical severity, and the vulnerability is publicly disclosed with potential exploitation tools available. While the EPSS score is not provided and the vulnerability is not yet listed in the CISA KEV catalog, the combination of a high CVSS score, remote attack vector, and known exploit code suggests a high likelihood of real-world exploitation.

Generated by OpenCVE AI on September 28, 2026 at 11:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest FAST FAC1200R firmware that patches the MmtAtePrase stack overflow.
  • If an update is unavailable, isolate the device by blocking or restricting external access to the vulnerable interfaces and limiting management traffic to trusted IP addresses.
  • Enable comprehensive logging and monitor the router for anomalous activity or error messages that may indicate exploitation attempts, and perform routine vulnerability scans on the network.

Generated by OpenCVE AI on September 28, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in FAST FAC1200R 5.0_20201119_1.0.2. Affected by this vulnerability is the function MmtAtePrase of the component MmtAtePrase Parser. This manipulation causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Title FAST FAC1200R MmtAtePrase stack-based overflow
First Time appeared Fast
Fast fac1200r
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:a:fast:fac1200r:*:*:*:*:*:*:*:*
Vendors & Products Fast
Fast fac1200r
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T10:53:39.470Z

Reserved: 2026-09-27T14:30:34.416Z

Link: CVE-2026-101038

cve-icon Vulnrichment

Updated: 2026-09-28T10:53:35.254Z

cve-icon NVD

Status : Received

Published: 2026-09-28T11:16:43.423

Modified: 2026-09-28T11:16:43.423

Link: CVE-2026-101038

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T11:30:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-121

    Stack-based Buffer Overflow