Junglewise Threat Intelligence

CVE-2021-27860: FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit

CVE-2021-27860 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-01-10

Technologies: Fatpipe WARP, Fatpipe IPVPN. Vendors: Fatpipe.

Executive brief

A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. This unrestricted file upload can lead to full system compromise.

Affected products

  • FatPipe WARP prior to 10.1.2r60p92 and 10.2.2r44p1
  • FatPipe IPVPN prior to 10.1.2r60p92 and 10.2.2r44p1
  • FatPipe MPVPN prior to 10.1.2r60p92 and 10.2.2r44p1

Timeline

  • 2021-11-17: disclosed: FBI/IC3 advisory released regarding exploitation
  • 2022-01-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-01-10: advisory: NVD publication date

Related threats