HIGH

CVE-2021-27860

Fatpipeinc Ipvpn Firmware 2021-12-08 CVSS v3.1
CVSS
8.8
KEV

Description

A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The FatPipe advisory identifier for this vulnerability is FPSA006.

Summary dbcve.org

This is an arbitrary file upload vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN. A remote, unauthenticated attacker can upload files to any location on the filesystem, enabling potential remote code execution by placing malicious files (e.g., web shells) in web-accessible directories.

Mitigation

Upgrade to versions 10.1.2r60p92 or 10.2.2r44p1 or later to patch the vulnerability. If immediate patching is not feasible, restrict network access to the web management interface using firewall rules or network segmentation.

Proof of Concept

Weakness (CWE)

CWE-434 Unrestricted File Upload

EPSS Score

39.82%
Probability of exploitation in next 30 days
98.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE