ZeroHour

Vulnerabilities

6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-27856
+4 in the same advisory: …27859 …27855 …27857 …27858
FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 includes an account named "cmuser" that has administrative privileges and n

FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 includes an account named "cmuser" that has administrative privileges and no password. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory identifier for this vulnerability is FPSA002.

NVD description · AI analysis pending
9.8
group max
6%
  • fatpipeinc ipvpn firmware
  • fatpipeinc mpvpn firmware
  • fatpipeinc warp firmware
CVE-2021-27860
Unauthenticated Arbitrary File Upload in FatPipe WARP, IPVPN, and MPVPN

CVE-2021-27860 is an unrestricted file upload flaw (CWE-434) in the web management interface of FatPipe WARP, IPVPN, and MPVPN appliances, allowing a remote, unauthenticated attacker to upload a file to any location on the device's filesystem. It is triggered simply by sending an upload request to the exposed management interface, with no credentials required. An attacker who abuses it can place files anywhere on the appliance, which can be used to tamper with device configurations or plant files that may enable further compromise or code execution. Any organization running an internet-exposed FatPipe WARP, IPVPN, or MPVPN device — typically deployed as edge/SD-WAN and WAN failover appliances at enterprise and branch sites — is affected. The flaw is confirmed exploited in the wild (added to CISA KEV on 2022-01-10), carries a high EPSS of 39.8% (99th percentile) for near-term exploitation, and while no public PoC is known, ransomware involvement is listed as unknown.

Do: Apply updates per vendor instructions, as required by CISA's KEV listing, since no specific fixed version numbers are provided in this data. In the interim, restrict access to the FatPipe web management interface with firewall rules or ACLs so it is not reachable from the internet. Check exposed devices for unexpected or recently modified files and configuration changes, given the unknown possibility of ransomware-related abuse.

8.840% KEV PoC
  • FatPipe WARP software
  • FatPipe IPVPN software
  • FatPipe MPVPN software
moderatelikely on the order of thousands to low tens of thousands of internet-exposed FatPipe appliances (estimate; no public scan count provided)