Executive brief
FastNetMon Community Edition, a tool used by network administrators to detect and mitigate DDoS attacks, contains a security flaw in how it handles BGP routing commands. An attacker with the ability to modify the software's configuration file can insert a specially crafted string that causes the program to crash or potentially execute unauthorized code when a DDoS attack is detected. This could allow an attacker to gain full control over the monitoring server or disable network protection during a critical event.
Technical details
A stack-based buffer overflow exists in 'src/actions/exabgp_action.cpp' within the 'exabgp_prefix_ban_manage()' function. The vulnerability is caused by the use of 'sprintf()' to format BGP commands into a fixed 256-byte stack buffer without bounds checking. While the prefix and next-hop variables are naturally bounded by IP address lengths, the 'exabgp_community' value is read directly from 'fastnetmon.conf' without length validation. An attacker with local access to the configuration file can provide a long community list (e.g., 30+ entries) to overflow the buffer by approximately 74+ bytes, overwriting the saved return address. Because the binary lacks modern protections like stack canaries (-fstack-protector) and PIE, this can lead to arbitrary code execution when the function returns during a DDoS mitigation event. As of May 2026, no official patch has been released.
Affected products
- FastNetMon FastNetMon Community Edition through 1.2.9
Timeline
- 2026-04-25: other: Vendor notified by Lorikeet Security
- 2026-05-23: disclosed: Public disclosure by Lorikeet Security
- 2026-05-26: advisory: CVE-2026-48696 published by MITRE/NVD