PT-2026-43311 · Unknown · Fastnetmon Community Edition

Published

2026-05-26

·

Updated

2026-05-27

·

CVE-2026-48693

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions FastNetMon Community Edition versions prior to 1.2.10
Description A local symlink attack is possible due to predictable file paths in the /tmp directory. The software uses a default statistics file path at '/tmp/fastnetmon.dat'. The print screen contents into file() function opens this path using std::ios::trunc without verifying if the path is a symbolic link or utilizing the O NOFOLLOW flag. Furthermore, the chmod() function incorrectly applies permissions to the cli stats file path regardless of the provided file path parameter. Because the umask is set to 0 during daemonization, created files become world-writable. A local attacker can leverage these conditions to overwrite arbitrary files with the privileges of the FastNetMon process user, which is typically root.
Recommendations Update to version 1.2.10 or later.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48693

Affected Products

Fastnetmon Community Edition