PatchSiren cyber security CVE debrief
CVE-2026-101039 FAST CVE debrief
A vulnerability was identified in FAST FAC1900R 20190827_2.0.2. Affected by this issue is the function copy_msg_element of the component devdiscover Service. Such manipulation leads to stack-based buffer overflow. The attack can be executed remotely. This vulnerability has a significant impact on network security, as it allows attackers to potentially execute arbitrary code on affected systems. Defenders should prioritize verifying the presence of affected versions and assessing exposure of the devdiscover Service.
- Vendor
- FAST
- Product
- FAC1900R
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-28
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-09-28
- Advisory updated
- 2026-09-28
Who should care
Defenders responsible for FAST FAC1900R deployments should assess exposure and prioritize verification of affected versions. They should also monitor for remote exploitation attempts and implement compensating controls to limit access to the devdiscover Service. Additionally, security teams and vulnerability management teams should be aware of the potential risks and impacts of this vulnerability.
Why it matters
Defenders should prioritize verifying the presence of affected FAST FAC1900R versions and assessing exposure of the devdiscover Service due to the risk of remote stack-based buffer overflow exploitation.
- Verify affected versions and assess exposure of the devdiscover Service
- Monitor for remote exploitation attempts
- Implement compensating controls to limit access to the devdiscover Service
Technical summary
The vulnerability affects the devdiscover Service in FAST FAC1900R 20190827_2.0.2, allowing for a stack-based buffer overflow via manipulation of the copy_msg_element function. This could potentially allow an attacker to execute arbitrary code on the affected system. The attack can be executed remotely, which increases the risk of exploitation. Defenders should prioritize verifying the presence of affected versions and assessing exposure of the devdiscover Service due to the risk of remote stack-based buffer overflow exploitation.
Defensive priority
Defenders should prioritize verifying the presence of affected versions and assessing exposure of the devdiscover Service.
Recommended defensive actions
- Verify the presence of affected FAST FAC1900R versions
- Assess exposure of the devdiscover Service
- Monitor for remote exploitation attempts
- Implement compensating controls to limit access to the devdiscover Service
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but vendor confirmation and additional context are limited. The exploit is publicly available and might be used. Further verification and monitoring are necessary to assess the actual risk and impact of this vulnerability. Defenders should verify the presence of affected FAST FAC1900R versions and assess exposure of the devdiscover Service.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-101039 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-101039
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-101039 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-101039
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/xiaobor123/vuls-find-VxWorks/tree/main/vul-find-FAST_FAC1900R-copy_msg_element(2)
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-101039
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/927251
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/410907
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/410907/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.