CVE-2026-48687
FastNetMon Community Edition up to version 1.2.9 has a flaw that lets attackers run arbitrary commands on the host. The vulnerability is in a PHP plugin that builds shell commands from untrusted input. It can be exploited without any user interaction.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
FastNetMon Community Edition (pavel-odintsov fastnetmon) versions 1.2.9 and earlier.
Real-world impact
An attacker could execute any shell command on the machine running FastNetMon, potentially taking full control, stealing data, or disrupting services.
Why this severity
The CVSS score of 9.8 reflects that the flaw allows remote attackers to run commands without authentication, giving them complete control over confidentiality, integrity, and availability of the affected system.
What to do about it
- ›Avoid invoking the vulnerable PHP script directly; restrict its execution to trusted contexts.
- ›Disable or remove the Juniper router integration plugin until a patch is released.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
NVD-referenced vendor advisory
Timeline
- May 26, 2026 · May 26, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 21, 2026 · 14d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- github.com/pavel-odintsov/fastnetmonproduct
- github.com/pavel-odintsov/fastnetmon/b…product
- lorikeetsecurity.com/blog/fastnetmon-cve-2026-48…exploitthird party advisory