CVE-2026-101354
A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affected element is the function _tWlanTask of the component MmtAte
CVSS
9.6
Critical
EPSS
0.4%
p30
KEV
—
Exploit Today
9
0-100
Published: Sep 29, 2026 · Last modified: Sep 29, 2026 · CWE-119 · CWE-121
Not enough EPSS history yet.
A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affected element is the function _tWlanTask of the component MmtAtePrase Parser. Performing a manipulation results in stack-based buffer overflow. The attacker must have access to the local network to execute the attack. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
- github.comhttps://github.com/xiaobor123/vuls-find-VxWorks/tree/main/vul-find-FAST_FAC1203R-twlantask-MmtAtePrase-stack-overflow(1)/vul-find-FAST_FAC1203R-twlantask-MmtAtePrase-stack-overflow
- vuldb.comhttps://vuldb.com/cve/CVE-2026-101354
- vuldb.comhttps://vuldb.com/submit/927238
- vuldb.comhttps://vuldb.com/vuln/411088
- vuldb.comhttps://vuldb.com/vuln/411088/cti
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-81433——
——0A stack-based buffer overflow vulnerability in WatchGuard Fireware OS's DHCP fingerprinting daemon (fingerd) allows an unauthenticated attacker with adjacent network access to execute arbitrary code or crash the process by sending a specially crafted DHCP packet.6hCVE-2026-18145——
——0A stack-based buffer overflow vulnerability in the spamBlocker (spamd) service of WatchGuard Fireware OS allows an authenticated attacker with administrator privileges to crash the service or potentially execute arbitrary code by sending a specially crafted management request.6hCVE-2026-1023028.8 HIG—
——0Buffer overflow in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)9hCVE-2026-7192——
——0A stack-based buffer overflow vulnerability in the Dbit T-CPE301K 4G WiFi minirouter allows an authenticated attacker to cause a denial of service (DoS) and a system reboot via a manipulated HTTP POST request directed at the endpoint ‘/js/common/do_cmd.js’ endpoint containing an excessively long parameter, which overwrites the PC and RA registers.9hCVE-2026-1008199.6 CRI—
——0Sandbox escape due to incorrect boundary conditions in the XPCOM component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.9hCVE-2026-1008148.8 HIG—
——0Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.9h