A critical stack-based buffer overflow in the MmtAtePrase parser of FAST FAC1200R firmware can be triggered remotely, and a public exploit exists but the vendor has not responded.
What Is It
CVE-2026-101038 is a stack-based buffer overflow (CWE-121, CWE-119) in the MmtAtePrase function of the MmtAtePrase Parser component in FAST FAC1200R. VulDB, the CNA, reports that manipulating this function corrupts the stack. The record says remote exploitation is possible. The public reference from the researcher places the flaw in the device's twlantask component on VxWorks.
NVD published the record on 2026-09-28. Its status is "Received," so NVD has not yet analyzed it.
Why It Matters
- Severity: CVSS 3.1 base score is 9.9 (CRITICAL), vector
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. It is network-reachable, has low attack complexity, needs only low privileges and no user interaction, and has a changed scope. Confidentiality, integrity and availability impact are all high. - CVSS 4.0: 8.6 (HIGH), with exploit maturity rated Proof-of-Concept.
- Public exploit: The record says the exploit "has been publicly disclosed and may be utilized."
- CISA SSVC: Exploitation is
poc, automatable isno, and technical impact istotal. - KEV status: CISA's Known Exploited Vulnerabilities catalog has no entry for this CVE. Active exploitation in the wild is not confirmed by KEV.
What's Vulnerable
- Vendor: FAST
- Product: FAC1200R
- Affected version: 5.0_20201119_1.0.2
- Component: MmtAtePrase Parser (
MmtAtePrasefunction) - CPE:
cpe:2.3:a:fast:fac1200r:*:*:*:*:*:*:*:*
The supplied data does not say whether other firmware versions are affected.
Patch Status
The source data lists no patch, fixed version or vendor advisory. According to the CNA, FAST was contacted early about the disclosure but did not respond. KEV has no entry, so there is no CISA required action or due date.
Owners of affected FAC1200R units should assume the device is unpatched. Limit network exposure of the device and watch the references below for updates.
Sources
- NVD / CVE record; CVE-2026-101038
- VulDB, CVE-2026-101038
- VulDB, Vulnerability entry 410906
- VulDB, CTI for 410906
- VulDB, Submission 927237
- Researcher write-up (GitHub, xiaobor123)
- CISA Known Exploited Vulnerabilities Catalog: no entry for this CVE