Executive Summary
A critical stack-based buffer overflow (CVE-2026-101037) has been disclosed in FAST FAC1200R consumer/SOHO routers, specifically in the parse_advertisement_frame function of the device's devdiscover service. The flaw is remotely exploitable without authentication or user interaction, and proof-of-concept exploit code is already public. As of publication, no vendor patch is available.
CVSS Score: 9.4 (Critical) — CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P
FAST is a router brand under the Tenda group, widely sold in home and small-office networking markets. Devices exposing the vulnerable devdiscover service on the network are at risk of denial of service or, depending on exploitation reliability, arbitrary code execution.
Vulnerability Overview
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-101037 |
| CVSS Score | 9.4 (Critical) |
| Type | Stack-Based Buffer Overflow (CWE-121) |
| Component | devdiscover Service — parse_advertisement_frame |
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | Low |
| User Interaction | None |
| Exploit Status | Public proof-of-concept available |
| Patch Status | None available at time of publication |
Affected Versions
| Product | Affected Firmware | Fixed Version |
|---|---|---|
| FAST FAC1200R | 5.0_20201119_1.0.2 | None available |
Researchers have also flagged closely related, but distinct, overflow issues in sibling FAST router models — including CVE-2026-101038 (MmtAtePrase Parser) and CVE-2026-101039 (copy_msg_element in FAST FAC1900R). Treat each CVE separately when tracking remediation, since they affect different components and device models.
How It Works
The devdiscover service on FAST FAC1200R routers processes device-advertisement frames on the local network. The parse_advertisement_frame function fails to properly bound-check attacker-controlled input before copying it into a fixed-size stack buffer, resulting in a classic stack-based overflow.
1. Attacker crafts a malicious device-advertisement frame
2. Frame is sent to the router's devdiscover service over the network
3. parse_advertisement_frame copies oversized input into a stack buffer
4. Stack memory is corrupted, overwriting adjacent data and return addresses
5. Result: service crash (DoS) or, with a reliable payload, arbitrary code executionBecause the attack requires only network access and low privileges — with no authentication or user interaction — any device that can reach the devdiscover service is a viable attack path.
Impact Assessment
| Impact Area | Description |
|---|---|
| Availability | Crashing the devdiscover service can disrupt device discovery and router stability |
| Confidentiality | Successful RCE would expose router configuration, credentials, and traffic |
| Integrity | An attacker gaining code execution could modify firmware behavior or implant persistence |
| Network Pivot | A compromised router provides a foothold onto the broader home/SOHO network |
| Public Exploit Risk | Availability of PoC code significantly lowers the bar for opportunistic attacks |
Remediation Guidance
Since FAST has not yet released a fix, mitigation is limited to network-level controls:
Immediate Steps
- Isolate affected devices from untrusted or public-facing networks — do not expose the devdiscover service to the internet.
- Segment IoT/router management traffic from sensitive internal networks using VLANs or firewall rules.
- Monitor for anomalous traffic targeting the devdiscover service, including malformed or oversized advertisement frames.
- Disable the devdiscover/device-discovery feature if the router firmware provides an option to turn it off.
- Check for firmware updates regularly — apply a fix immediately once FAST publishes one.
If a Patch Is Not Released
Consider replacing affected devices with hardware that has active vendor support, particularly in any environment where the router is internet-facing.
Detection Indicators
| Indicator | Description |
|---|---|
| Malformed advertisement frames | Traffic targeting the devdiscover service with unusually large or malformed payloads |
| Unexpected device reboots | Router crashing or restarting without a known cause |
| Unusual outbound connections | Possible sign of post-exploitation activity after successful RCE |