CVE-2021-27860
Arbitrary file upload vulnerability in FatPipe software
In short
An unauthenticated attacker can upload files anywhere on the FatPipe server without permission, potentially installing malicious software or taking control of the system.
Technical detail
CWE-434 arbitrary file upload in the web management interface allows unauthenticated remote attackers to write files to arbitrary filesystem locations; no authentication is required, and successful exploitation enables arbitrary code execution and full system compromise.
Summary generated and translated by AI from the official description.
A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The FatPipe advisory identifier for this vulnerability is FPSA006.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →