CVE-2026-101037 is a critical, remotely reachable stack-based buffer overflow in the devdiscover service of the FAST FAC1200R. A public exploit exists, and the vendor has not responded to disclosure.
What Is It
CVE-2026-101037 is a stack-based buffer overflow in the parse_advertisement_frame function of the devdiscover Service on the FAST FAC1200R, firmware version 5.0_20201119_1.0.2. The CNA (VulDB) classifies it as CWE-121 (Stack-based Buffer Overflow) and CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer). The record says the attack can be launched remotely.
The CVE was published on 2026-09-28. NVD lists its status as "Received", which means NVD has not finished its own analysis yet. All scoring and affected-product data below comes from VulDB.
Why It Matters
VulDB rates this issue 9.9 CRITICAL under CVSS 3.1 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H):
- It can be exploited over the network.
- Attack complexity is low.
- It needs only low privileges and no user interaction.
- Scope is changed, with high impact to confidentiality, integrity, and availability.
The secondary scores are:
- CVSS 4.0: 8.6 HIGH, with exploit maturity marked as Proof-of-Concept.
- CVSS 2.0: 9.0.
According to the NVD description, "the exploit has been made public and could be used." A public PoC lowers the bar for attackers. However, this CVE has no entry in the CISA KEV catalog, so KEV does not confirm that it is being exploited in the wild.
What's Vulnerable
- Vendor: FAST
- Product: FAC1200R
- Affected version: 5.0_20201119_1.0.2
- Component: devdiscover Service (
parse_advertisement_frame) - CPE:
cpe:2.3:a:fast:fac1200r:*:*:*:*:*:*:*:*
The record lists no other affected versions.
Patch Status
There is no patch or vendor advisory in the source data. The disclosure says the vendor "was contacted early about this disclosure but did not respond in any way." Because this CVE is not in the KEV catalog, CISA has not set a required action or due date. Owners of affected FAC1200R devices should treat them as unpatched and watch the vendor and VulDB references for updates.