Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 27 May 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:pavel-odintsov:fastnetmon:*:*:*:*:community:*:*:* |
Wed, 27 May 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Symlink Attack via Predictable Temporary File in FastNetMon |
Tue, 26 May 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Symlink Attack Allows Root File Overwrite in FastNetMon Community Edition | |
| Weaknesses | CWE-22 CWE-284 |
Tue, 26 May 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-59 | |
| Metrics |
cvssV3_1
|
Tue, 26 May 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pavel-odintsov
Pavel-odintsov fastnetmon |
|
| Vendors & Products |
Pavel-odintsov
Pavel-odintsov fastnetmon |
Tue, 26 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Symlink Attack Allows Root File Overwrite in FastNetMon Community Edition | |
| Weaknesses | CWE-22 CWE-284 |
Tue, 26 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FastNetMon Community Edition through 1.2.9 is vulnerable to a local symlink attack via predictable file paths in /tmp. The statistics file path defaults to '/tmp/fastnetmon.dat' (src/fastnetmon.cpp line 159). The print_screen_contents_into_file() function (src/fastnetmon_logic.cpp line 2186) opens this path with std::ios::trunc without checking for symlinks or using O_NOFOLLOW. Additionally, the chmod() call on line 2190 always operates on cli_stats_file_path regardless of which file_path parameter was passed (a bug that applies wrong permissions), and the umask is set to 0 during daemonization (src/fastnetmon.cpp line 1821), making all created files world-writable. A local attacker can exploit this to overwrite arbitrary files as the FastNetMon process user (typically root). | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-26T20:33:37.827Z
Reserved: 2026-05-22T00:00:00.000Z
Link: CVE-2026-48693
Updated: 2026-05-26T20:31:06.082Z
Status : Analyzed
Published: 2026-05-26T17:16:53.807
Modified: 2026-06-17T10:55:11.630
Link: CVE-2026-48693
No data.
OpenCVE Enrichment
Updated: 2026-05-27T00:30:20Z