OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-101037

CRITICAL · CVSS 9.9 EPSS 0.46% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

A stack-based buffer overflow vulnerability exists in the parse_advertisement_frame function of the devdiscover Service in FAST FAC1200R 5.0_20201119_1.0.2, allowing remote attackers to exploit the flaw. This critical vulnerability, with a CVSS score of 9.9, poses a significant risk of unauthorized access or system compromise. Organizations using this product should prioritize immediate remediation efforts, especially given the public availability of the exploit and the vendor's lack of response.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-101037
Severity
CRITICAL
CVSS
9.9
EPSS
0.46%

Original NVD Description

A vulnerability was found in FAST FAC1200R 5.0_20201119_1.0.2. Affected is the function parse_advertisement_frame of the component devdiscover Service. The manipulation results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.