CVE-2026-101354 Details
Description
A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affected element is the function _tWlanTask of the component MmtAtePrase Parser. Performing a manipulation results in stack-based buffer overflow. The attacker must have access to the local network to execute the attack. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
A stack-based buffer overflow vulnerability has been identified in the FAST FAC1203R router, specifically in the firmware version 20200116_2.0.4. The issue arises in the MmtAtePrase parsing function, which is accessed through the _tWlanTask UDP handler. An attacker on the local network can exploit this vulnerability by sending a crafted UDP packet to port 1060, using the wioctl command prefix and an oversized argument. The vulnerability has been publicly disclosed and is available for exploitation.
Users are advised to restrict access to UDP port 1060 to trusted management networks, filter untrusted UDP packets on an upstream gateway or local firewall, and avoid exposing vendor-private management or discovery services to the WAN side. No official patch is currently available, but users should monitor the vendor's website for updates.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/xiaobor123/vuls-find-VxWorks/tree/main/vul-find-FAST_FAC1203R-twlantask-MmtAtePrase-stack-overflow(1)/vul-find-FAST_FAC1203R-twlantask-MmtAtePrase-stack-overflow | [email protected] | ExploitTechnical Analysis |
| https://vuldb.com/cve/CVE-2026-101354 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/927238 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/411088 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/411088/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| FAST FAC1203R | 20200116_2.0.4 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion