Junglewise Threat Intelligence

CVE-2026-48693: FastNetMon Community Edition symlink attack in /tmp statistics file

CVE-2026-48693 · Severity: info · CVSS 7 · Published 2026-05-26

Technologies: FastNetMon Community Edition.

Executive brief

FastNetMon Community Edition, a DDoS detection tool, is vulnerable to a local security flaw that allows an attacker to overwrite critical system files. By exploiting predictable temporary file locations, a local user can trick the software into deleting or modifying files it has permission to access, typically with root privileges. This can lead to a complete system crash or unauthorized changes to system configurations.

Technical details

FastNetMon Community Edition (up to v1.2.9) uses a predictable default statistics file path at /tmp/fastnetmon.dat. The function print_screen_contents_into_file() in src/fastnetmon_logic.cpp opens this path using std::ios::trunc without verifying if the path is a symbolic link or using the O_NOFOLLOW flag. Furthermore, the application sets a umask of 0 during daemonization, resulting in world-writable files, and contains a logic error in its chmod() calls. A local attacker can create a symlink at the predictable /tmp location pointing to a sensitive system file; when FastNetMon updates its statistics, it will truncate and overwrite the target file with the privileges of the FastNetMon process (often root).

Affected products

  • FastNetMon FastNetMon Community Edition through 1.2.9

Timeline

  • 2026-05-23: advisory: Lorikeet Security published detailed technical blog post
  • 2026-05-26: disclosed: CVE-2026-48693 published to NVD

References