PT-2026-94244 · Fatpipe · Mpvpn+2
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FatPipe MPVPN version 10.1.2r60p100
FatPipe WARP version 10.1.2r60p100
FatPipe IPVPN version 10.1.2r60p100
Description
An OS command injection issue exists in the xtremed daemon. An unauthenticated remote attacker with access to the management interface can send crafted input to the 'AuthFormServlet' endpoint, which causes authentication data to be processed by a shell, allowing the execution of arbitrary commands with root privileges.
Recommendations
Upgrade version 10.1.2r60p100 to a current supported release.
Restrict management access to trusted administrative networks.
Use WAN access control lists to limit access to trusted sources.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ipvpn
Mpvpn
Warp