Cyber & AI intelligence
Wasteland.
Briefs indexed2910
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-101038 2026-09-28

FAST FAC1200R Stack Overflow in MmtAtePrase Parser (CVE-2026-101038)

"A critical stack-based buffer overflow in the MmtAtePrase parser of FAST FAC1200R firmware can be triggered remotely, and a public exploit exists but the vendor has not responded."

A critical stack-based buffer overflow in the MmtAtePrase parser of FAST FAC1200R firmware can be triggered remotely, and a public exploit exists but the vendor has not responded.

What Is It

CVE-2026-101038 is a stack-based buffer overflow (CWE-121, CWE-119) in the MmtAtePrase function of the MmtAtePrase Parser component in FAST FAC1200R. VulDB, the CNA, reports that manipulating this function corrupts the stack. The record says remote exploitation is possible. The public reference from the researcher places the flaw in the device's twlantask component on VxWorks.

NVD published the record on 2026-09-28. Its status is "Received," so NVD has not yet analyzed it.

Why It Matters

What's Vulnerable

The supplied data does not say whether other firmware versions are affected.

Patch Status

The source data lists no patch, fixed version or vendor advisory. According to the CNA, FAST was contacted early about the disclosure but did not respond. KEV has no entry, so there is no CISA required action or due date.

Owners of affected FAC1200R units should assume the device is unpatched. Limit network exposure of the device and watch the references below for updates.

Sources