CVSS 9.9 router bug: scary number, tiny blast radius

A freshly disclosed flaw in a Chinese-market Wi-Fi router is rated almost as severe as a vulnerability can get, but the catch is in who actually owns one.

The headline number

CVE-2026-101037 landed in the National Vulnerability Database on 28 September with a CVSS score of 9.9 - about as close to “maximum severity” as these things get. That alone tends to set off alarm bells. But a critical score only tells you how bad things could be if the flaw is reachable and exploitable in the real world, not how many people are actually exposed. Worth unpacking before anyone panics.

What the bug actually does

The vulnerability sits inside a specific piece of hardware: the FAST FAC1200R, a dual-band AC1200 Wi-Fi router, running firmware version V5.0_20201119_1.0.2. According to the NVD summary, the flaw lives in a function called parse_advertisement_frame, part of something called the “devdiscover” service on the device. Feed it a malformed input and it overflows a stack-based buffer - a classic memory-corruption bug that can, in the right circumstances, let an attacker crash the service or potentially run their own code on the router.

A proof-of-concept writeup on GitHub ties this to the same firmware build and includes a demonstration video showing the crash being triggered. The router runs VxWorks, an embedded real-time operating system commonly found in consumer networking kit, industrial controllers and similar low-level devices - not something most people will have heard of, but it’s everywhere behind the scenes.

So who is actually at risk

This is where the “critical” label needs a reality check. FAST (also styled Fastcom, 迅捷) is a Chinese networking brand whose products are sold and firmware-documented primarily for the Chinese domestic market. The firmware version named in both the NVD entry and the GitHub repository is specific - V5.0_20201119_1.0.2 - meaning this isn’t a flaw stretching across every router the company has ever made, let alone every router sold in the UK.

Crucially, none of the available sources confirm:

  • Whether a patch exists. There’s no mention of a fixed firmware release or vendor advisory in either source.
  • Whether it’s being exploited. This looks like responsible (or at least independent) security research, not an active attack campaign.
  • How many devices are actually affected. No install-base figures are given anywhere in the sourcing.

For a UK reader, the realistic exposure is low. This isn’t a router widely stocked by British ISPs or retailers, and the devdiscover service in question typically needs to be reachable - either on the local network or, in a worse-case misconfiguration, exposed to the internet - for the bug to matter at all.

What to do about it

If you happen to own a FAST FAC1200R, the sensible move is to check Fastcom’s firmware download page for an update, and in the meantime make sure the router’s management and discovery services aren’t exposed to the open internet - good practice for any home router regardless of this specific bug. Everyone else can safely file this under “not your problem.”

The takeaway

A 9.9 CVSS score sounds terrifying, but severity scores measure potential impact, not how many people are sat in the blast zone. This is a real, demonstrated flaw in a single firmware build of a niche router mostly sold outside the UK, with no confirmed patch and no evidence of active exploitation yet. Worth tracking if you’re in network security; not worth losing sleep over if you’re an ordinary reader checking their own kit.

Sources