CVE-2026-48686
FastNetMon Community Edition up to version 1.2.9 contains a stack‑based buffer overflow in its BGP packet decoder. A specially crafted BGP packet can cause the program to write beyond a 4‑byte buffer, allowing an attacker to execute arbitrary code. The flaw is triggered by an unvalidated prefix length field in the packet.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
pavel-odintsov fastnetmon Community Edition, versions up to 1.2.9.
Real-world impact
An attacker who can send BGP packets to the vulnerable FastNetMon instance can overflow a stack buffer and run arbitrary code, potentially taking full control of the host running the service.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability can be exploited remotely over the network without authentication or user interaction, and it gives an attacker full control over confidentiality, integrity, and availability of the affected system.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- May 26, 2026 · May 26, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- github.com/pavel-odintsov/fastnetmonproduct
- github.com/pavel-odintsov/fastnetmon/b…product
- lorikeetsecurity.com/blog/fastnetmon-cve-2026-48…third party advisory