Fastnetmon
Vendor:
First CVE: Dec 15, 2024 · Active for 1 year
16
Total CVEs
More Total CVEs than 93% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Fastnetmon over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 15, 2024
19 months ago
Most Recent CVE
May 26, 2026
63 days ago
CVE Severity & Scoring
Fastnetmon16 CVEs
25%
50%
25%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (18.8%)
Network12 (75.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (6.3%)
Attack Complexity
Low15 (93.8%)
High1 (6.3%)
Unknown0 (0.0%)
User Interaction
None16 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low5 (31.3%)
High0 (0.0%)
None11 (68.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-48686CRITICAL FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflow in the BGP NLRI (Network Layer Reachability Information) decoder. The function decode_bgp_subnet_e | May 26, 2026 | 9.8 | 40 | NO | NO |
CVE-2026-48689CRITICAL FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the dynamic_binary_buffer_t class (src/dynamic_binary_buffer.hpp). Five methods (app | May 26, 2026 | 9.8 | 40 | NO | NO |
CVE-2026-48687CRITICAL FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integration plugin. The _log() function in src/juniper_plugin/fastne | May 26, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-48691CRITICAL FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp_protocol.hpp, the IPv4UnicastAnnounce::get_attributes() fun | May 26, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-48695HIGH FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _log() function in src/mikrotik_plugin/fast | May 26, 2026 | 8.1 | 32 | NO | NO |
CVE-2026-48692HIGH FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The server is initialized with grpc::InsecureServerCredentials( | May 26, 2026 | 8.1 | 32 | NO | NO |
CVE-2026-48694HIGH FastNetMon Community Edition through 1.2.9 contains a configuration injection vulnerability in the Juniper router integration plugin. In src/juniper_plugin/fastnetmon_juniper.php, | May 26, 2026 | 8.1 | 31 | NO | NO |
CVE-2026-48688HIGH FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds reads in the BGP MP_REACH_NLRI IPv6 attribute decoder. The function decode_mp_reach_ipv6() in src/bgp_pro | May 26, 2026 | 7.5 | 31 | NO | NO |
CVE-2026-48690HIGH FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet capture buffer allocation. In src/packet_storage.hpp, the allocate_buffer() func | May 26, 2026 | 7.1 | 30 | NO | NO |
CVE-2026-48697HIGH FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HTTPS connections. The execute_web_request_secure() function in src/fast_library.cpp creates | May 26, 2026 | 7.4 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Fastnetmon
Top CWEs
Versions
No cataloged versions.