CVE-2021-27860
Description
A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The FatPipe advisory identifier for this vulnerability is FPSA006.
Summary dbcve.org
This is an arbitrary file upload vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN. A remote, unauthenticated attacker can upload files to any location on the filesystem, enabling potential remote code execution by placing malicious files (e.g., web shells) in web-accessible directories.
Mitigation
Upgrade to versions 10.1.2r60p92 or 10.2.2r44p1 or later to patch the vulnerability. If immediate patching is not feasible, restrict network access to the web management interface using firewall rules or network segmentation.