PT-2026-94245 · Fatpipe · Mpvpn+2

·

CVE-2026-90823

·

Published

2026-09-17

·

Updated

2026-09-22

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FatPipe MPVPN version 10.1.2r60p100 FatPipe WARP version 10.1.2r60p100 FatPipe IPVPN version 10.1.2r60p100
Description A stack-based buffer overflow exists in the /usr/sbin/auth user pass function. An unauthenticated remote attacker with access to the management interface can send a crafted authentication request that triggers an unchecked copy into a fixed-size stack buffer, potentially leading to arbitrary code execution with root privileges. The management interface is disabled by default and requires manual activation by the user to be accessible.
Recommendations Upgrade version 10.1.2r60p100 to a current supported release. Restrict management access to trusted administrative networks. Use WAN access control lists to limit access to trusted sources.

Fix

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90823

Affected Products

Ipvpn
Mpvpn
Warp