Executive brief
FastNetMon Community Edition, a DDoS detection tool, fails to verify the identity of servers when sending telemetry data over HTTPS. This allows a network-positioned attacker to intercept and modify sensitive system information, such as CPU details, kernel versions, and traffic statistics. This flaw undermines the security of the encrypted connection, potentially exposing operational data to unauthorized parties.
Technical details
The vulnerability exists in the execute_web_request_secure() function within src/fast_library.cpp. While the code initializes a Boost.Asio SSL context and loads system CA certificates, it fails to call set_verify_mode(boost::asio::ssl::verify_peer). Consequently, the underlying OpenSSL library defaults to verify_none, allowing the TLS handshake to succeed regardless of certificate validity, expiration, or hostname mismatch. An attacker capable of intercepting network traffic (e.g., via DNS spoofing or BGP hijacking) can present a self-signed or arbitrary certificate to decrypt and modify the telemetry stream sent to community-stats.fastnetmon.com. This stream contains system fingerprinting data including CPU models, software versions, and traffic statistics.
Affected products
- FastNetMon LTD FastNetMon Community Edition Up to and including 1.2.9
Timeline
- 2026-04-25: disclosed: Lorikeet Security notified FastNetMon LTD
- 2026-05-23: advisory: Lorikeet Security published detailed findings
- 2026-05-26: advisory: CVE-2026-48697 published to NVD