Junglewise Threat Intelligence

CVE-2026-48691: FastNetMon Community Edition heap overflow in BGP AS_PATH encoder

CVE-2026-48691 · Severity: info · CVSS 7.5 · Published 2026-05-26

Technologies: FastNetMon LTD FastNetMon Community Edition. Vendors: FastNetMon LTD.

Executive brief

FastNetMon Community Edition, a DDoS detection and traffic analysis tool, contains a vulnerability in how it handles network routing information. When the software processes or forwards routing updates with long path data, it incorrectly calculates the size of the memory needed to store that data. This error can allow a remote attacker to crash the service or potentially gain unauthorized control over the system by sending specially crafted network messages.

Technical details

An integer overflow exists in the BGP AS_PATH attribute encoder within `src/bgp_protocol.hpp`. The function `IPv4UnicastAnnounce::get_attributes()` calculates the `attribute_length` for an AS_PATH but stores the result in a `uint8_t` variable. When an AS_PATH contains more than 63 ASNs, the length calculation (2 + ASNs * 4) exceeds 255 and silently truncates. This truncated value is used to allocate a heap buffer via `set_maximum_buffer_size()`, but the subsequent loop writes the full, untruncated list of 32-bit ASNs into the undersized buffer. An attacker can trigger this by injecting long AS_PATHS via BGP peers or through the unauthenticated gRPC API's `ExecuteBan` method, potentially leading to remote code execution. As of May 2026, no official patch has been released.

Affected products

  • FastNetMon LTD FastNetMon Community Edition through 1.2.9

Timeline

  • 2026-04-25: other: Vendor notified by Lorikeet Security
  • 2026-05-23: advisory: Public disclosure by Lorikeet Security
  • 2026-05-26: disclosed: CVE-2026-48691 published to NVD

References

Related threats