Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-96257: Fast FAC1203R Gigabit Edition remote code execution risk

CVE-2026-96257 · published today
Summary

The Device Discovery Service in Fast FAC1203R Gigabit Edition version 2.0.4 can be tricked into overwriting its own memory, which could let an attacker run their own code from anywhere on the network. This could lead to loss of control over the device or data theft. Apply any available firmware updates from the vendor or disable the Device Discovery Service until a fix is released.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
fast fac1203r gigabit edition 2.0.4
Original advisory text
Fast FAC1203R Gigabit Edition Device Discovery Service copy_msg_element stack-based overflow
A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this issue is the function copy_msg_element of the component Device Discovery Service. Executing a manipulation can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity
9.3 Critical
CVSS 2.0: 10.0 (NVD)
CVSS 3.1: 10.0 (NVD)
CVSS 4.0: 9.3 (NVD)
Type
CWE-119Buffer Overflow
CWE-121Stack-based Buffer Overflow
Timeline
Published23 Sep 2026
Updated23 Sep 2026
First seen23 Sep 2026
Sources
CVE-2026-96257 · MITRE
Track software like this
Free during beta