A critical stack-based buffer overflow in the Device Discovery Service of Fast FAC1203R Gigabit Edition 2.0.4 can be triggered remotely without authentication, and a public exploit already exists.
What Is It
CVE-2026-96257 is a stack-based buffer overflow (CWE-121, CWE-119) in the copy_msg_element function of the Device Discovery Service component in Fast FAC1203R Gigabit Edition 2.0.4. An attacker can manipulate input to the service to overflow a stack buffer. The attack is executed remotely and requires no privileges and no user interaction.
The issue was assigned a CVSS v3.1 base score of 10.0 (Critical): vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, with a changed scope and full compromise of confidentiality, integrity, and availability. The CVSS v4.0 assessment from the CNA scores it 9.3 (Critical) and rates exploit maturity as Proof-of-Concept.
Why It Matters
Two factors make this urgent. First, the exploit has been published and may already be in use; proof-of-concept code is referenced publicly alongside the disclosure. Second, the vendor was contacted early in the disclosure process and did not respond in any way, meaning no coordinated fix accompanied publication.
The vulnerable component is a device discovery service; the kind of network-facing listener that is typically enabled by default on consumer and SOHO networking gear and reachable from the local network segment without credentials. A scope-changed CVSS rating indicates impact beyond the vulnerable component itself.
This CVE does not appear in the CISA Known Exploited Vulnerabilities catalog at the time of writing, so there is no confirmed in-the-wild exploitation and no federally mandated remediation deadline.
What's Vulnerable
- Vendor: Fast
- Product: FAC1203R Gigabit Edition
- Affected version: 2.0.4
- Component: Device Discovery Service (
copy_msg_elementfunction) - CPE:
cpe:2.3:a:fast:fac1203r_gigabit_edition:*:*:*:*:*:*:*:*
Patch Status
No patch is available. The vendor did not respond to the disclosure attempt, and the NVD record lists no vendor advisory or fixed version. The record remains in "Received" status as of its 2026-09-23 publication date. With no fix on offer, restricting network reachability of the Device Discovery Service and isolating affected devices are the only mitigations supported by the available data.