CVE-2026-48689Disclosure(pavel-odintsov / fastnetmon)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch pavel-odintsov fastnetmon systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the dynamic_binary_buffer_t class (src/dynamic_binary_buffer.hpp). Five methods (append_dynamic_buffer, append_data_as_pointer, append_data_as_object_ptr, memcpy_from_ptr, memcpy_from_object_ptr) use an incorrect bounds check of the form 'if (offset + length > maximum_internal_storage_size + 1)' instead of the correct 'if (offset + length > maximum_internal_storage_size)'. This allows writing exactly one byte past the end of the heap-allocated buffer. The class is used pervasively in BGP message encoding/decoding, NetFlow template processing, and Flow Spec NLRI construction. An attacker who can send network traffic (NetFlow, sFlow, IPFIX, or BGP) to a FastNetMon instance can trigger this overflow, potentially achieving arbitrary code execution by corrupting heap metadata. Notably, the append_byte() method uses the correct bounds check, confirming the inconsistency.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787CWE-122CWE-193

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fastnetmon

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-27); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
fastnetmon

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-27: 2Mentions · 2026-06-03: 1PoC Mentioned / Linked · 2026-06-03: 1Patch / Workaround · 2026-05-27: 2Patch / Workaround · 2026-06-03: 1Technical Details · 2026-05-27: 2Technical Details · 2026-06-03: 105-2706-03
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets16 URLs
Classification over time
DateTotalLabels
2026-05-272
Disclosure1Patch1
2026-06-031
Disclosure1
Full discourse3 posts
  • Lorikeet Security@lorikeetsec
    Disclosure

    16 CVEs in FastNetMon Community Edition. All found, reported, and fixed. Our team ran a full source code audit of FastNetMon CE and surfaced 16 distinct vulnerabilities, now tracked as CVE-2026-48682 through CVE-2026-48697. First, credit where it is due. Huge thanks to Pavel Odintsov and the FastNetMon team. We sent the report and they moved immediately, confirmed the issues, staged fixes, and shipped patches in days. That is exactly how responsible disclosure is supposed to go, and a maintainer who turns it around that fast makes the whole ecosystem safer. The part I am most excited about: we did not find these by hand alone. Much of this audit ran on the same analysis engine we are building into Lory, our autonomous offensive security agent. The pattern that caught most of the worst bugs is simple to describe and brutal in practice, a length value read straight off the wire flowing into a memcpy with no bounds check. Teaching an agent to trace untrusted input from the network boundary to the dangerous sink is exactly what Lory is built to do at scale. FastNetMon was a real-world proving ground, and it delivered. The throughline on the critical ones: wire-controlled length, no validation, into a binary built with zero hardening flags. No stack canary, no FORTIFY, no PIE, no RELRO. That is what turns a parser bug into code execution as root on the box watching your network. If you run FastNetMon CE in production, update now. If you package it yourself, add hardening flags to your build. → All 16, with full technical writeups: Memory corruption CVE-2026-48682 · IPv4 parser OOB read https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48682-ipv4-parser-oob CVE-2026-48683 · NetFlow v9 data flowset OOB https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48683-netflow-v9-data-oob CVE-2026-48684 · NetFlow v9 options template OOB https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48684-netflow-v9-options-oob CVE-2026-48685 · BGP extended length misread https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48685-bgp-extended-length CVE-2026-48686 · BGP NLRI stack overflow (CVSS 9.8, RCE) https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48686-bgp-nlri-stack-overflow CVE-2026-48688 · BGP MP_REACH_NLRI IPv6 https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48688-bgp-mp-reach-nlri-ipv6 CVE-2026-48689 · Dynamic buffer off-by-one https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48689-dynamic-buffer-off-by-one CVE-2026-48690 · Packet storage integer overflow https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48690-packet-storage-integer-overflow CVE-2026-48691 · BGP AS_PATH overflow https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48691-bgp-as-path-overflow Injection CVE-2026-48687 · Juniper plugin command injection https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48687-juniper-cmd-injection CVE-2026-48694 · Juniper NETCONF injection https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48694-juniper-netconf-injection CVE-2026-48695 · MikroTik command injection https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48695-mikrotik-cmd-injection CVE-2026-48696 · ExaBGP sprintf overflow https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48696-exabgp-sprintf-overflow Auth & transport CVE-2026-48692 · Unauthenticated gRPC interface https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48692-grpc-no-auth CVE-2026-48693 · Symlink issue in temp handling https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48693-symlink-tmp CVE-2026-48697 · Missing TLS validation https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48697-missing-tls-validation → Read the C, find the line, prove the impact, disclose it right. #cybersecurity #infosec #vulnerabilityresearch #CVE #networksecurity #BGP #responsibledisclosure #AISecurity

    Post summary

    The text announces 16 newly discovered CVEs in FastNetMon CE, links to detailed technical writeups, and urges users to apply vendor patches and hardening measures.

    00041338
    299 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-48689 — CVSS 9.8/10 ██████████ FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/Mb3qM0U2rC

    Post summary

    The tweet discloses CVE-2026-48689 affecting FastNetMon Community Edition, details an off-by-one heap buffer overflow (CVSS 9.8), and notes that a patch is available.

    20010102
    43 followersView on X
  • Orizon@OrizonCyber
    Disclosure

    🚨 CVE-2026-48689 — CVSS 9.8/10 ██████████ FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the... Severity: CRITICAL Patch now. #cybersecurity #CVE

    Post summary

    The tweet announces the critical heap-based buffer overflow vulnerability CVE-2026-48689 affecting FastNetMon Community Edition through 1.2.9, notes its severity, and informs that a patch is now available.

    1000064
    43 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppavel-odintsovfastnetmon---

Explore more