Junglewise Threat Intelligence

CVE-2026-48687: FastNetMon Community Edition OS command injection in Juniper plugin

CVE-2026-48687 · Severity: info · CVSS 8.1 · Published 2026-05-26

Technologies: FastNetMon Community Edition.

Executive brief

FastNetMon Community Edition, a DDoS detection and mitigation tool, contains a security flaw in its Juniper router integration plugin. This plugin is responsible for logging attack details and updating router configurations when a threat is detected. An attacker who can influence the data processed by this plugin—such as the reported attack IP address—could potentially execute arbitrary commands on the server. This could lead to a complete system takeover, unauthorized access to network hardware, or disruption of network security operations.

Technical details

An OS command injection vulnerability exists in the `_log()` function within `src/juniper_plugin/fastnetmon_juniper.php`. The function constructs a shell command by concatenating unsanitized command-line arguments (`argv[1]` through `argv[3]`, representing the attack IP, direction, and power) into an `exec()` call used for logging. While the current C++ core typically passes safe dotted-decimal IP addresses, the PHP script lacks any input validation or shell escaping. An attacker can exploit this by supplying shell metacharacters (e.g., backticks or semicolons) in the input fields, leading to arbitrary command execution with the privileges of the user running the script (often root). The vulnerability can be triggered via the attack notification pipeline or direct script invocation. As of the advisory date, no official patch has been released; recommended fixes include using `file_put_contents()` or `escapeshellarg()`.

Affected products

  • FastNetMon FastNetMon Community Edition through 1.2.9

Timeline

  • 2026-04-25: disclosed: Lorikeet Security notified FastNetMon LTD
  • 2026-05-23: advisory: Lorikeet Security published detailed advisory
  • 2026-05-26: disclosed: CVE-2026-48687 published to NVD

References