CVE-2026-48687

FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integration plugin. The _log() function in src/juniper_plugin/fastnetmon_juniper.php (lines 117-118) constructs shell commands by concatenating the $msg parameter directly into exec() calls: exec("echo `date` \"- {FASTNETMON] - " . $msg . " \" >> " . $FILE_LOG_TMP). The $msg variable contains unsanitized data derived from command-line arguments argv[1] through argv[3], which represent the attack IP address, direction, and power. While FastNetMon's C++ core currently passes IP addresses via inet_ntoa() (which only produces safe dotted-decimal notation), the PHP script performs no input validation or shell escaping. If the script is invoked directly, by another orchestration system, or if future code changes pass string-sourced IPs, arbitrary commands can be injected. The correct fix is to replace exec() with file_put_contents() or use escapeshellarg() on all parameters.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pavel-odintsov:fastnetmon:*:*:*:*:community:*:*:*

History

21 Jul 2026, 19:10

Type Values Removed Values Added
Summary
  • (es) FastNetMon Community Edition hasta la versión 1.2.9 contiene una vulnerabilidad de inyección de comandos del sistema operativo en el plugin de integración del router Juniper. La función _log() en src/juniper_plugin/fastnetmon_juniper.php (líneas 117-118) construye comandos de shell concatenando el parámetro $msg directamente en las llamadas a exec(): exec('echo 'date' \"- {FASTNETMON] - ' . $msg . ' \" >> ' . $FILE_LOG_TMP). La variable $msg contiene datos no saneados derivados de los argumentos de línea de comandos argv[1] a argv[3], que representan la dirección IP de ataque, la dirección y la potencia. Si bien el núcleo C++ de FastNetMon actualmente pasa direcciones IP a través de inet_ntoa() (que solo produce notación decimal con puntos segura), el script PHP no realiza validación de entrada ni escape de shell. Si el script se invoca directamente, por otro sistema de orquestación, o si futuros cambios de código pasan direcciones IP de origen de cadena, se pueden inyectar comandos arbitrarios. La solución correcta es reemplazar exec() con file_put_contents() o usar escapeshellarg() en todos los parámetros.

27 May 2026, 14:15

Type Values Removed Values Added
First Time Pavel-odintsov
Pavel-odintsov fastnetmon
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:pavel-odintsov:fastnetmon:*:*:*:*:community:*:*:*
CWE CWE-78
References () https://github.com/pavel-odintsov/fastnetmon - () https://github.com/pavel-odintsov/fastnetmon - Product
References () https://github.com/pavel-odintsov/fastnetmon/blob/master/src/juniper_plugin/fastnetmon_juniper.php - () https://github.com/pavel-odintsov/fastnetmon/blob/master/src/juniper_plugin/fastnetmon_juniper.php - Product
References () https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48687-juniper-cmd-injection - () https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48687-juniper-cmd-injection - Exploit, Third Party Advisory

26 May 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-26 16:16

Updated : 2026-07-21 19:10


NVD link : CVE-2026-48687

Mitre link : CVE-2026-48687

CVE.ORG link : CVE-2026-48687


JSON object : View

Products Affected

pavel-odintsov

  • fastnetmon
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')