{"id":"CVE-2026-48687","title":"FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integration plugin","summary":"FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integration plugin. The _log() function in src/juniper_plugin/fastnetmon_juniper.php (lines 117-118) constructs shell command…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-78","CWE-78"],"vendor":"pavel-odintsov","product":"fastnetmon","affected":["fastnetmon <= 1.2.9"],"published":"2026-05-26","updated":"2026-07-21","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-48687","references":[{"url":"https://github.com/pavel-odintsov/fastnetmon","label":"cve@mitre.org"},{"url":"https://github.com/pavel-odintsov/fastnetmon/blob/master/src/juniper_plugin/fastnetmon_juniper.php","label":"cve@mitre.org"},{"url":"https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48687-juniper-cmd-injection","label":"cve@mitre.org"}],"tags":["nvd"],"epss":0.02652,"epssPercentile":0.85014,"ingestedAt":"2026-07-22T13:03:41.015Z","slug":"CVE-2026-48687","body":"## Overview\n\nFastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integration plugin. The _log() function in src/juniper_plugin/fastnetmon_juniper.php (lines 117-118) constructs shell commands by concatenating the $msg parameter directly into exec() calls: exec(\"echo `date` \\\"- {FASTNETMON] - \" . $msg . \" \\\" >> \" . $FILE_LOG_TMP). The $msg variable contains unsanitized data derived from command-line arguments argv[1] through argv[3], which represent the attack IP address, direction, and power. While FastNetMon's C++ core currently passes IP addresses via inet_ntoa() (which only produces safe dotted-decimal notation), the PHP script performs no input validation or shell escaping. If the script is invoked directly, by another orchestration system, or if future code changes pass string-sourced IPs, arbitrary commands can be injected. The correct fix is to replace exec() with file_put_contents() or use escapeshellarg() on all parameters.\n\n## Affected\n\n- `fastnetmon <= 1.2.9`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.5,"exploitation":0,"ransomware":0},"changes":[]}