CVE Explorer
CVE-2026-48688
FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds reads in the BGP MP_REACH_NLRI IPv6 attribute decoder. The function decode_mp_reach_ipv6() in src/bgp_protocol.cpp contains a TODO comment at line 156 explicitly acknowledging 'we should add sanity checks to avoid reads after attribute memory block.' The function casts raw pointers to structure types without verifying sufficient data exists (line 158), uses the attacker-controlled length_of_next_hop field to determine mem
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"description":"n/a","lang":"en","type":"text"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a866fbfc6af2684afccbf43ec91bbbb590c3d87305d381aa8686be111b7e27f2 · sha256:3e2e09774ba294aa… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-125","description":"CWE-125 Out-of-bounds Read","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a866fbfc6af2684afccbf43ec91bbbb590c3d87305d381aa8686be111b7e27f2 · sha256:3e2e09774ba294aa… · /containers/adp/0/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:a866fbfc6af2684afccbf43ec91bbbb590c3d87305d381aa8686be111b7e27f2 · sha256:3e2e09774ba294aa… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:a866fbfc6af2684afccbf43ec91bbbb590c3d87305d381aa8686be111b7e27f2 · sha256:3e2e09774ba294aa… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"description":"n/a","lang":"en","type":"text"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a866fbfc6af2684afccbf43ec91bbbb590c3d87305d381aa8686be111b7e27f2 · sha256:3e2e09774ba294aa… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-125","description":"CWE-125 Out-of-bounds Read","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a866fbfc6af2684afccbf43ec91bbbb590c3d87305d381aa8686be111b7e27f2 · sha256:3e2e09774ba294aa… · /containers/adp/0/problemTypes/0/descriptions/0
Source references
3 source assertions{"url":"https://github.com/pavel-odintsov/fastnetmon"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a866fbfc6af2684afccbf43ec91bbbb590c3d87305d381aa8686be111b7e27f2 · sha256:3e2e09774ba294aa… · /containers/cna/references/0
{"url":"https://github.com/pavel-odintsov/fastnetmon/blob/master/src/bgp_protocol.cpp"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a866fbfc6af2684afccbf43ec91bbbb590c3d87305d381aa8686be111b7e27f2 · sha256:3e2e09774ba294aa… · /containers/cna/references/1
{"url":"https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48688-bgp-mp-reach-nlri-ipv6"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a866fbfc6af2684afccbf43ec91bbbb590c3d87305d381aa8686be111b7e27f2 · sha256:3e2e09774ba294aa… · /containers/cna/references/2
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.