Impact
FAST FAC1900R 20190827_2.0.2 contains a stack‑based buffer overflow in the copy_msg_element function of the devdiscover Service. The flaw allows an attacker to overwrite the stack, which can lead to arbitrary code execution. The vulnerability is rated CVSS 10, indicating the maximum severity. It is identified as CWE‑119 and CWE‑121. The public exploit is available and the attack can be carried out remotely without authentication.
Affected Systems
The affected product is FAST FAC1900R, version 20190827_2.0.2. The vulnerability is tied to the devdiscover Service component in this specific build.
Risk and Exploitability
The CVSS score of 10 and the availability of a public exploit signal a high likelihood of real‑world exploitation. Because the EPSS score is not available, the risk is based on the evidence of public exploitation and the remote attack vector. The device is exposed to remote attackers that can trigger the overflow via the devdiscover Service. The vendor has not provided a response or patch at this time, so the vulnerability remains unmitigated in deployed systems.
OpenCVE Enrichment