Executive brief
FastNetMon is a DDoS detection tool that can automatically instruct network routers to block malicious traffic. A vulnerability in its Juniper router integration allows an attacker to bypass security controls and send unauthorized commands to the router. This could lead to a complete takeover of the router, allowing attackers to modify routing tables, disable firewalls, or create backdoor administrative accounts.
Technical details
A configuration injection vulnerability exists in the Juniper NETCONF plugin (`src/juniper_plugin/fastnetmon_juniper.php`) of FastNetMon Community Edition. The `$IP_ATTACK` variable, sourced from command-line arguments, is interpolated directly into Junos CLI configuration strings without validation or sanitization. By embedding newline characters (`\n`) into the IP address string, an attacker can inject arbitrary `set` or `delete` commands into the NETCONF session. This allows for unauthorized modification of any configuration element accessible via the plugin's credentials, including routing policies, firewall filters, and system users. As of May 2026, no official patch has been released.
Affected products
- FastNetMon LTD FastNetMon Community Edition through 1.2.9
Timeline
- 2026-04-25: other: Vendor notified by Lorikeet Security
- 2026-05-23: advisory: Public advisory released by Lorikeet Security
- 2026-05-26: disclosed: CVE published to NVD