Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 17 Jun 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | MikroTik Plugin OS Command Injection in FastNetMon Community Edition |
Tue, 16 Jun 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | MikroTik Plugin OS Command Injection in FastNetMon Community Edition |
Wed, 27 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:pavel-odintsov:fastnetmon:*:*:*:*:community:*:*:* |
Tue, 26 May 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | FastNetMon Community Edition MikroTik Plugin OS Command Injection |
Tue, 26 May 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pavel-odintsov
Pavel-odintsov fastnetmon |
|
| Vendors & Products |
Pavel-odintsov
Pavel-odintsov fastnetmon |
|
| Metrics |
cvssV3_1
|
Tue, 26 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | FastNetMon Community Edition MikroTik Plugin OS Command Injection | |
| Weaknesses | CWE-78 |
Tue, 26 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _log() function in src/mikrotik_plugin/fastnetmon_mikrotik.php (lines 107-108) constructs shell commands by concatenating the $msg parameter directly into exec() calls: exec("echo `date` \"- {FASTNETMON] - " . $msg . " \" >> " . $FILE_LOG_TMP). This is identical in pattern to the Juniper plugin vulnerability. The $msg variable contains unsanitized attack data from command-line arguments. An attacker who can influence argv[] values can inject arbitrary shell commands. The fix is to replace exec() with file_put_contents() or use escapeshellarg(). | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-26T20:17:41.811Z
Reserved: 2026-05-22T00:00:00.000Z
Link: CVE-2026-48695
Updated: 2026-05-26T20:16:15.931Z
Status : Analyzed
Published: 2026-05-26T18:16:52.950
Modified: 2026-06-17T10:55:12.607
Link: CVE-2026-48695
No data.
OpenCVE Enrichment
Updated: 2026-06-18T07:45:03Z