SECURITYCRITICALCVE-2026-101037

Critical Stack Overflow in FAST FAC1200R Routers Has Public Exploit

CVE-2026-101037 lets remote attackers crash or hijack FAST FAC1200R routers via the devdiscover service; a public exploit exists and no patch is available.

Dylan H.

Security Team

September 29, 2026
4 min read
Critical Stack Overflow in FAST FAC1200R Routers Has Public Exploit

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • FAST FAC1200R firmware 5.0_20201119_1.0.2

Executive Summary

A critical stack-based buffer overflow (CVE-2026-101037) has been disclosed in FAST FAC1200R consumer/SOHO routers, specifically in the parse_advertisement_frame function of the device's devdiscover service. The flaw is remotely exploitable without authentication or user interaction, and proof-of-concept exploit code is already public. As of publication, no vendor patch is available.

CVSS Score: 9.4 (Critical) — CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P

FAST is a router brand under the Tenda group, widely sold in home and small-office networking markets. Devices exposing the vulnerable devdiscover service on the network are at risk of denial of service or, depending on exploitation reliability, arbitrary code execution.


Vulnerability Overview

AttributeValue
CVE IDCVE-2026-101037
CVSS Score9.4 (Critical)
TypeStack-Based Buffer Overflow (CWE-121)
Componentdevdiscover Service — parse_advertisement_frame
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
Exploit StatusPublic proof-of-concept available
Patch StatusNone available at time of publication

Affected Versions

ProductAffected FirmwareFixed Version
FAST FAC1200R5.0_20201119_1.0.2None available

Researchers have also flagged closely related, but distinct, overflow issues in sibling FAST router models — including CVE-2026-101038 (MmtAtePrase Parser) and CVE-2026-101039 (copy_msg_element in FAST FAC1900R). Treat each CVE separately when tracking remediation, since they affect different components and device models.


How It Works

The devdiscover service on FAST FAC1200R routers processes device-advertisement frames on the local network. The parse_advertisement_frame function fails to properly bound-check attacker-controlled input before copying it into a fixed-size stack buffer, resulting in a classic stack-based overflow.

1. Attacker crafts a malicious device-advertisement frame
2. Frame is sent to the router's devdiscover service over the network
3. parse_advertisement_frame copies oversized input into a stack buffer
4. Stack memory is corrupted, overwriting adjacent data and return addresses
5. Result: service crash (DoS) or, with a reliable payload, arbitrary code execution

Because the attack requires only network access and low privileges — with no authentication or user interaction — any device that can reach the devdiscover service is a viable attack path.


Impact Assessment

Impact AreaDescription
AvailabilityCrashing the devdiscover service can disrupt device discovery and router stability
ConfidentialitySuccessful RCE would expose router configuration, credentials, and traffic
IntegrityAn attacker gaining code execution could modify firmware behavior or implant persistence
Network PivotA compromised router provides a foothold onto the broader home/SOHO network
Public Exploit RiskAvailability of PoC code significantly lowers the bar for opportunistic attacks

Remediation Guidance

Since FAST has not yet released a fix, mitigation is limited to network-level controls:

Immediate Steps

  1. Isolate affected devices from untrusted or public-facing networks — do not expose the devdiscover service to the internet.
  2. Segment IoT/router management traffic from sensitive internal networks using VLANs or firewall rules.
  3. Monitor for anomalous traffic targeting the devdiscover service, including malformed or oversized advertisement frames.
  4. Disable the devdiscover/device-discovery feature if the router firmware provides an option to turn it off.
  5. Check for firmware updates regularly — apply a fix immediately once FAST publishes one.

If a Patch Is Not Released

Consider replacing affected devices with hardware that has active vendor support, particularly in any environment where the router is internet-facing.


Detection Indicators

IndicatorDescription
Malformed advertisement framesTraffic targeting the devdiscover service with unusually large or malformed payloads
Unexpected device rebootsRouter crashing or restarting without a known cause
Unusual outbound connectionsPossible sign of post-exploitation activity after successful RCE

References