Executive brief
FatPipe's MPVPN, WARP, and IPVPN appliances are WAN optimization and VPN devices used to manage multi-site network connectivity. An unauthenticated attacker with network access to the management interface (which is disabled by default) can send a crafted request to trigger a buffer overflow in the authentication service, potentially gaining complete control of the appliance. This impacts network availability and security across connected sites.
Technical details
A stack-based buffer overflow exists in the /usr/sbin/auth_user_pass binary on affected appliances. The vulnerability is triggered when an unchecked copy operation writes attacker-controlled data into a fixed-size stack buffer, allowing stack corruption and arbitrary code execution as root. The attack vector is the management interface (typically disabled by default); an attacker must first gain network access to this interface through misconfiguration or network exposure. While no active exploitation in the wild has been reported, the 9.8 CVSS score reflects the severity—authentication is not required and code execution as root is achievable. FatPipe has marked firmware version 10.1.2r60p100 as end-of-life; customers must upgrade to supported releases for a patch.
Affected products
- FatPipe MPVPN 10.1.2r60p100
- FatPipe WARP 10.1.2r60p100
- FatPipe IPVPN 10.1.2r60p100
Timeline
- 2026-09-17: disclosed