Executive brief
Fast FAC1203R is a Gigabit router used in network infrastructure. A stack-based buffer overflow in the Device Discovery Service component allows remote attackers to execute arbitrary code without authentication. An attacker can exploit this remotely to compromise the router and potentially pivot to other network devices.
Technical details
A stack-based buffer overflow vulnerability exists in the copy_msg_element function of the Device Discovery Service component in FAC1203R Gigabit Edition. The vulnerability is remotely exploitable without requiring authentication, and public exploit code has been published. A successful exploit results in arbitrary code execution with the privileges of the affected service.
Affected products
- Fast FAC1203R Gigabit Edition 2.0.4
Timeline
- 2026-09-23: disclosed
- other: Exploit published; vendor unresponsive