rootpwn

critical · CVSS v3 9.6 · CVSS v4 9.4

CVE-2026-101354

A stack-based buffer overflow exists in the _tWlanTask function of the MmtAtePrase Parser in FAST FAC1203R firmware 20200116_2.0.4. The flaw

Overview

A stack-based buffer overflow exists in the _tWlanTask function of the MmtAtePrase Parser in FAST FAC1203R firmware 20200116_2.0.4. The flaw can be triggered by a local network attacker and may allow arbitrary code execution. The vulnerability is rated critical with a CVSS v3 score of 9.6.

Description

A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affected element is the function _tWlanTask of the component MmtAtePrase Parser. Performing a manipulation results in stack-based buffer overflow. The attacker must have access to the local network to execute the attack. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Impact

The overflow can lead to confidentiality, integrity, and availability compromise on affected devices. Local network attackers can execute arbitrary code, potentially taking control of the device and the network segment. Network administrators and users of the device are directly impacted.

Remediation

Apply any vendor-released firmware update that patches the _tWlanTask function. If no patch is available, isolate the device from the local network or block traffic to the vulnerable port. Monitor logs for suspicious activity and consider disabling the MmtAtePrase Parser if possible.

Risk context

The vulnerability is classified as critical with a CVSS v3 score of 9.6 and no EPSS data, indicating a high urgency for remediation.

Affected products

  • FAST FAC1203R
  • MmtAtePrase Parser

Scores

Severity
critical
CVSS v2
8.3
CVSS v3
9.6
CVSS v4
9.4
EPSS
—

buffer-overflow local-network critical stack-overflow FAST FAC1203R MmtAtePrase

← All CVEs