Pavel-odintsov

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 18
    Known Exploited: 0
    2
    Critical Level Threats
    10
    High Level Threats
    6
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-48682

    FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the IPv4 packet parser. In src/simple_packet_parser_ng.cpp, after validating that the packet contains at least sizeof(ipv4_header_t) bytes (20 bytes), the code advances the local_pointer by '4 * ipv4_header->get_ihl()' (line 164) without validating that (a) IHL >= 5 (the minimum valid value per RFC 791), or (b) 4 * IHL bytes are actually available in the packet. The IHL field is 4 bits, allowing values 0-15, so the advance can be 0-60 bytes. An IHL value of 15 with only 20 bytes validated causes a 40-byte over-read. An IHL of 0-4 causes the pointer to not advance past the IP header, resulting in the TCP/UDP header being parsed from IP header data (type confusion). This vulnerability is reachable via any packet capture interface.

    Last Modified: Jun 04, 2026
    Published: Jun 02, 2026

    CVE-2026-48683

    Out-of-Bounds Read in FastNetMon NetFlow v9 Collector

    Last Modified: May 27, 2026
    Published: May 26, 2026

    CVE-2026-48697

    FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HTTPS connections. The execute_web_request_secure() function in src/fast_library.cpp creates a boost::asio::ssl::context with tls_client mode and calls set_default_verify_paths() to load CA certificates, but never calls set_verify_mode(boost::asio::ssl::verify_peer). Without this call, OpenSSL performs the TLS handshake without validating the server's certificate chain, making all HTTPS connections vulnerable to man-in-the-middle attacks. This function is used for telemetry reporting to community-stats.fastnetmon.com, which sends system information including CPU model, kernel version, traffic statistics, and software configuration. An attacker can intercept and modify this data or redirect it to a malicious server.

    Last Modified: May 27, 2026
    Published: May 26, 2026

    CVE-2026-48696

    Buffer Overflow in FastNetMon Community Edition Exposes Remote Code Execution Risk

    Last Modified: May 27, 2026
    Published: May 26, 2026

    CVE-2026-48694

    FastNetMon Juniper NETCONF Configuration Injection

    Last Modified: May 27, 2026
    Published: May 26, 2026
    Items Per Page
    Pavel-Odintsov Vulnerabilities & Security CVEs | CVE-DB