Fastcom maintains a narrow portfolio of networking and remote-access appliances, including models such as the FAC1200R, FAC1900R, and FW300R series, with observed vulnerabilities clustering around memory-safety issues in firmware implementations. The durable signal centers on buffer overflow and out-of-bounds write conditions, weakness classes typical of embedded device codebases where input validation and bounds checking are inconsistently applied across the product line. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fastcom over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-50399CRITICAL FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter password. | Nov 26, 2025 | 9.8 | 34 | NO | NO |
CVE-2024-41285CRITICAL A stack overflow in FAST FW300R v1.3.13 Build 141023 Rel.61347n allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via a crafted file path. | Aug 26, 2024 | 9.8 | 31 | NO | NO |
CVE-2025-50402CRITICAL FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter string fac_password. | Nov 26, 2025 | 9.8 | 30 | NO | NO |
CVE-2022-26988HIGH TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MntAte` function. Local users could get remote cod | May 10, 2022 | 7.8 | 27 | NO | NO |
CVE-2022-26987HIGH TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePrase` function. Local users could get remot | May 10, 2022 | 7.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fastcom.
Media articles that mention a CVE ID that affects a product developed by Fastcom — matched by CVE ID, not by vendor name.