Vulnerability record · CVE-2021-27860 · published 8 December 2021
CVE-2021-27860: FatPipe WARP/IPVPN/MPVPN web interface unrestricted file upload
Fatpipeinc · Ipvpn Firmware
The web management interface of FatPipe WARP, IPVPN and MPVPN before 10.1.2r60p92 and 10.2.2r44p1 allows an unauthenticated remote attacker to upload a file to any location on the filesystem. Because the upload is unrestricted, an attacker can place executable or configuration content anywhere, which can lead to full compromise of the appliance.
Description
A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The FatPipe advisory identifier for this vulnerability is FPSA006.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is an unauthenticated network-reachable file upload flaw with public exploit references and CISA KEV listing, making active exploitation likely.
What it is
The web management interface of FatPipe WARP, IPVPN and MPVPN before 10.1.2r60p92 and 10.2.2r44p1 allows an unauthenticated remote attacker to upload a file to any location on the filesystem. Because the upload is unrestricted, an attacker can place executable or configuration content anywhere, which can lead to full compromise of the appliance.
Impact
An attacker can write arbitrary files to the device filesystem, enabling code execution or configuration tampering and potentially full control of the affected appliance.
Attack surface
Reachable over the network through the web management interface with no authentication required, though the CVSS vector indicates user interaction is required (UI:R).
Exploitation
CVE-2021-27860 is listed in CISA KEV with a due date of 2022-01-24, and EPSS shows a 30-day probability of roughly 0.40 (98.5th percentile); references are tagged Exploit, indicating public exploit activity.
What to do
- Apply the vendor updates to versions 10.1.2r60p92 / 10.2.2r44p1 or later as instructed in the FatPipe advisory.
- Restrict network access to the web management interface to trusted management networks only.
- Disable or block external exposure of the management interface until patching is complete.
- Review the appliance filesystem and configuration for unauthorized files or changes.
- Monitor vendor and CISA guidance for any additional required actions.
Detection
- Inspect web server and application logs for file upload requests to unexpected paths or with unusual filenames.
- Monitor the filesystem for new or modified files outside expected directories.
- Alert on management interface access from untrusted or external source addresses.
- Correlate upload activity with subsequent process execution or configuration changes on the appliance.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-27860 to the Known Exploited Vulnerabilities catalog on 10 January 2022 as "FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit". Required action: Apply updates per vendor instructions. Federal deadline 24 January 2022.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.fatpipeinc.com/support/cve-list.php | Vendor Advisory |
| https://www.ic3.gov/Media/News/2021/211117-2.pdf | ExploitMitigationThird Party AdvisoryUS Government Resource |
| https://www.fatpipeinc.com/support/cve-list.php | Vendor Advisory |
| https://www.ic3.gov/Media/News/2021/211117-2.pdf | ExploitMitigationThird Party AdvisoryUS Government Resource |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-27860 | US Government Resource |
Track CVE-2021-27860 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-27860), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.