FastNetMon Community Edition through 1.2.9 is vulnerable to a local symlink attack via predictable file paths in /tmp. The statistics file path defaults to '/tmp/fastnetmon.dat' (src/fastnetmon.cpp line 159). The printscreencontentsintofile() function (src/fastnetmonlogic.cpp line 2186) opens this path with std::ios::trunc without checking for symlinks or using ONOFOLLOW. Additionally, the chmod() call on line 2190 always operates on clistatsfilepath regardless of which filepath parameter was passed (a bug that applies wrong permissions), and the umask is set to 0 during daemonization (src/fastnetmon.cpp line 1821), making all created files world-writable. A local attacker can exploit this to overwrite arbitrary files as the FastNetMon process user (typically root).