CVE-2021-27860

FatPipe WARP, FatPipe IPVPN, FatPipe MPVPN

Published 8 Dec 2021 · updated 17 Jun 2026 · Analyzed

8.8 High · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 10 Jan 2022, with a remediation deadline of 24 Jan 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The FatPipe advisory identifier for this vulnerability is FPSA006.

References