PT-2026-43312 · Debian+2 · Fastnetmon

Published

2026-05-26

·

Updated

2026-05-26

·

CVE-2026-48697

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions FastNetMon Community Edition versions prior to 1.2.10
Description The software fails to verify TLS certificates on outbound HTTPS connections. The execute web request secure() function in src/fast library.cpp initializes a boost::asio::ssl::context in tls client mode and loads CA certificates via set default verify paths(), but it does not invoke set verify mode(boost::asio::ssl::verify peer). Consequently, OpenSSL completes the TLS handshake without validating the server's certificate chain, enabling man-in-the-middle attacks. This issue affects telemetry reporting to the endpoint 'community-stats.fastnetmon.com', which transmits system data such as CPU model, kernel version, traffic statistics, and software configuration. An attacker could intercept, modify, or redirect this information to a malicious server.
Recommendations Update to version 1.2.10 or later.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48697

Affected Products

Fastnetmon