← back
CVE-2021-27860

Arbitrary file upload vulnerability in FatPipe software

CVSS 9.8 CRITICALEPSS 39.8%● KEVCWE-434
In short

An unauthenticated attacker can upload files anywhere on the FatPipe server without permission, potentially installing malicious software or taking control of the system.

Technical detail

CWE-434 arbitrary file upload in the web management interface allows unauthenticated remote attackers to write files to arbitrary filesystem locations; no authentication is required, and successful exploitation enables arbitrary code execution and full system compromise.

Summary generated and translated by AI from the official description.
A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The FatPipe advisory identifier for this vulnerability is FPSA006.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →