CVE-2021-27860
FatPipe WARP, FatPipe IPVPN, FatPipe MPVPN
Published 8 Dec 2021 · updated 17 Jun 2026 · Analyzed
8.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 10 Jan 2022, with a remediation deadline of 24 Jan 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The FatPipe advisory identifier for this vulnerability is FPSA006.
References
- www.fatpipeinc.com/support/cve-list.php · Vendor Advisory
- www.ic3.gov/Media/News/2021/211117-2.pdf · Exploit, Mitigation, Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-27860 · US Government Resource