Junglewise Threat Intelligence

CVE-2026-48686: FastNetMon Community Edition stack overflow in BGP NLRI decoder

CVE-2026-48686 · Severity: info · CVSS 9.8 · Published 2026-05-26

Technologies: FastNetMon Community Edition.

Executive brief

FastNetMon is a high-performance DDoS sensor used by network administrators to monitor traffic and detect attacks. A critical vulnerability in its BGP protocol handling allows a remote attacker to execute malicious code on the system. By sending a specially crafted BGP message, an attacker can crash the service or gain full control over the monitoring server, potentially leading to a complete compromise of the network monitoring infrastructure.

Technical details

A stack-based buffer overflow exists in the `decode_bgp_subnet_encoding_ipv4_raw()` function within `src/bgp_protocol.cpp`. The function reads a `prefix_bit_length` value directly from a BGP packet without validating that it is within the expected range for IPv4 (0-32). This value is used to calculate a copy length of up to 32 bytes, which is then passed to `memcpy()` to populate a 4-byte `uint32_t` stack variable. An attacker can overflow the stack by up to 28 bytes, overwriting the saved return address. Because the software is often compiled without stack canaries or Position Independent Executable (PIE) protections, this provides a reliable primitive for remote code execution. The vulnerability is reachable via any BGP peer session.

Affected products

  • FastNetMon FastNetMon Community Edition through 1.2.9

Timeline

  • 2026-05-23: disclosed: Vulnerability details published by Lorikeet Security
  • 2026-05-26: advisory: CVE-2026-48686 published in NVD

References