- Description
- FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the dynamic_binary_buffer_t class (src/dynamic_binary_buffer.hpp). Five methods (append_dynamic_buffer, append_data_as_pointer, append_data_as_object_ptr, memcpy_from_ptr, memcpy_from_object_ptr) use an incorrect bounds check of the form 'if (offset + length > maximum_internal_storage_size + 1)' instead of the correct 'if (offset + length > maximum_internal_storage_size)'. This allows writing exactly one byte past the end of the heap-allocated buffer. The class is used pervasively in BGP message encoding/decoding, NetFlow template processing, and Flow Spec NLRI construction. An attacker who can send network traffic (NetFlow, sFlow, IPFIX, or BGP) to a FastNetMon instance can trigger this overflow, potentially achieving arbitrary code execution by corrupting heap metadata. Notably, the append_byte() method uses the correct bounds check, confirming the inconsistency.
- Source
- cve@mitre.org
- NVD status
- Modified
- Products
- fastnetmon
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- Hype score
- Not currently trending
๐จ CVE-2026-48689 โ CVSS 9.8/10 โโโโโโโโโโ FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the... Severity: CRITICAL Patch now. #cybersecurity #CVE
@OrizonCyber
27 May 2026
62 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
๐จ CVE-2026-48689 โ CVSS 9.8/10 โโโโโโโโโโ FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/Mb3qM0U2rC
@OrizonCyber
27 May 2026
93 Impressions
0 Retweets
1 Like
0 Bookmarks
2 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:pavel-odintsov:fastnetmon:*:*:*:*:community:*:*:*",
"matchCriteriaId": "E712A01F-3AD7-4CC2-9A8B-F8C63756EBBF",
"versionEndIncluding": "1.2.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]