Vulnerability Description
FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _log() function in src/mikrotik_plugin/fastnetmon_mikrotik.php (lines 107-108) constructs shell commands by concatenating the $msg parameter directly into exec() calls: exec("echo `date` \"- {FASTNETMON] - " . $msg . " \" >> " . $FILE_LOG_TMP). This is identical in pattern to the Juniper plugin vulnerability. The $msg variable contains unsanitized attack data from command-line arguments. An attacker who can influence argv[] values can inject arbitrary shell commands. The fix is to replace exec() with file_put_contents() or use escapeshellarg().
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pavel-Odintsov | Fastnetmon | <= 1.2.9 |
Related Weaknesses (CWE)
References
- https://github.com/pavel-odintsov/fastnetmonProduct
- https://github.com/pavel-odintsov/fastnetmon/blob/master/src/mikrotik_plugin/fasProduct
- https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48695-mikrotik-cmd-injectiThird Party Advisory
FAQ
What is CVE-2026-48695?
CVE-2026-48695 is a vulnerability with a CVSS score of 8.1 (HIGH). FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _log() function in src/mikrotik_plugin/fastnetmon_mikrotik.php ...
How severe is CVE-2026-48695?
CVE-2026-48695 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-48695?
Check the references section above for vendor advisories and patch information. Affected products include: Pavel-Odintsov Fastnetmon.