CVE-2026-48691
FastNetMon Community Edition up to version 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. The overflow occurs when an AS_PATH contains more than 63 ASNs, causing a heap buffer overflow that can crash the program or allow arbitrary code execution. The flaw is triggered by a crafted BGP update and requires no user interaction.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
pavel-odintsov fastnetmon Community Edition, versions 1.2.9 and earlier, used by network operators and security teams monitoring BGP traffic.
Real-world impact
An attacker can send a malicious BGP update with a very long AS_PATH to a vulnerable FastNetMon instance, causing the service to crash or potentially execute arbitrary code. This could lead to denial of service or compromise of the monitoring system.
Why this severity
The CVSS score of 9.8 reflects the lack of required privileges or user interaction, combined with complete confidentiality, integrity, and availability impact due to the heap buffer overflow. The vulnerability is highly exploitable and can be used to take full control of the affected system.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- May 26, 2026 · May 26, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- github.com/pavel-odintsov/fastnetmonproduct
- github.com/pavel-odintsov/fastnetmon/b…product
- lorikeetsecurity.com/blog/fastnetmon-cve-2026-48…third party advisory