CVE-2026-48695: FastNetMon MikroTik Command Injection
CVE-2026-48695: OS command injection and hardcoded api/api123 credentials in FastNetMon's MikroTik plugin. CVS...
8 min read →Detect and mitigate DDoS attacks in under 1 second, respond automatically, and keep your users informed.
All features →From indie hosts to ISPs, see how teams like yours use Flowtriq to detect and stop DDoS attacks.
All Use Cases → Talk to Us →Blog
Practical guides from engineers who've been DDoS'd and learned from it.
16 CVEs disclosed in FastNetMon Community Edition 1.2.9 - two critical RCE, command injection, hardcoded credentials, and unauthenticated APIs. Full breakdown.
CVE-2026-48695: OS command injection and hardcoded api/api123 credentials in FastNetMon's MikroTik plugin. CVS...
8 min read →CVE-2026-48687: OS command injection in FastNetMon's Juniper plugin logging function. Attacker-controlled data...
7 min read →CVE-2026-48694: configuration injection in FastNetMon's Juniper plugin allows full router compromise via NETCO...
8 min read →CVE-2026-48696: stack buffer overflow in FastNetMon's ExaBGP action handler. A 256-byte sprintf buffer overflo...
7 min read →CVE-2026-48692: FastNetMon's gRPC API runs without authentication. Any local process can trigger IP bans and w...
8 min read →CVE-2026-48697: FastNetMon skips TLS certificate verification on telemetry connections. Any MITM can intercept...
7 min read →Three out-of-bounds read vulnerabilities in FastNetMon's NetFlow v9 and IPv4 parsers. CVE-2026-48683, CVE-2026...
10 min read →Four BGP parser vulnerabilities in FastNetMon CE including a critical 9.8 CVSS stack overflow. CVE-2026-48686,...
12 min read →Three memory safety and file handling vulnerabilities in FastNetMon CE, including a critical 9.8 CVSS off-by-o...
10 min read →A critical 9.1 CVSS vulnerability in Mirai's CNC server allows remote denial of service without authentication...
12 min read →