← Vulnerability feed

Vulnerability record · CVE-2021-27860 · published 8 December 2021

CVE-2021-27860: FatPipe WARP/IPVPN/MPVPN web interface unrestricted file upload

Fatpipeinc · Ipvpn Firmware

The web management interface of FatPipe WARP, IPVPN and MPVPN before 10.1.2r60p92 and 10.2.2r44p1 allows an unauthenticated remote attacker to upload a file to any location on the filesystem. Because the upload is unrestricted, an attacker can place executable or configuration content anywhere, which can lead to full compromise of the appliance.

8.8 CVSS 3.1 High CISA KEV since 10 Jan 2022 EPSS 40% · top 1.4% CWE-434 · Unrestricted file upload
8.8CVSS 3.1 base score, v2 9.3
40%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The FatPipe advisory identifier for this vulnerability is FPSA006.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is an unauthenticated network-reachable file upload flaw with public exploit references and CISA KEV listing, making active exploitation likely.

What it is

The web management interface of FatPipe WARP, IPVPN and MPVPN before 10.1.2r60p92 and 10.2.2r44p1 allows an unauthenticated remote attacker to upload a file to any location on the filesystem. Because the upload is unrestricted, an attacker can place executable or configuration content anywhere, which can lead to full compromise of the appliance.

Impact

An attacker can write arbitrary files to the device filesystem, enabling code execution or configuration tampering and potentially full control of the affected appliance.

Attack surface

Reachable over the network through the web management interface with no authentication required, though the CVSS vector indicates user interaction is required (UI:R).

Exploitation

CVE-2021-27860 is listed in CISA KEV with a due date of 2022-01-24, and EPSS shows a 30-day probability of roughly 0.40 (98.5th percentile); references are tagged Exploit, indicating public exploit activity.

What to do

  • Apply the vendor updates to versions 10.1.2r60p92 / 10.2.2r44p1 or later as instructed in the FatPipe advisory.
  • Restrict network access to the web management interface to trusted management networks only.
  • Disable or block external exposure of the management interface until patching is complete.
  • Review the appliance filesystem and configuration for unauthorized files or changes.
  • Monitor vendor and CISA guidance for any additional required actions.

Detection

  • Inspect web server and application logs for file upload requests to unexpected paths or with unusual filenames.
  • Monitor the filesystem for new or modified files outside expected directories.
  • Alert on management interface access from untrusted or external source addresses.
  • Correlate upload activity with subsequent process execution or configuration changes on the appliance.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-27860 to the Known Exploited Vulnerabilities catalog on 10 January 2022 as "FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit". Required action: Apply updates per vendor instructions. Federal deadline 24 January 2022.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.fatpipeinc.com/support/cve-list.php Vendor Advisory
https://www.ic3.gov/Media/News/2021/211117-2.pdf ExploitMitigationThird Party AdvisoryUS Government Resource
https://www.fatpipeinc.com/support/cve-list.php Vendor Advisory
https://www.ic3.gov/Media/News/2021/211117-2.pdf ExploitMitigationThird Party AdvisoryUS Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-27860 US Government Resource

Track CVE-2021-27860 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-27856Fatpipeinc ipvpn firmware vulnerabilityFatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 includes an account named "cmuser" that has administrative privi…EPSS 5.6%8.8CVE-2021-27859Fatpipeinc ipvpn firmware missing authorization vulnerabilityA missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 1…EPSS 1.6%8.8CVE-2021-27855Fatpipeinc ipvpn firmware missing authorization vulnerabilityFatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote, authenticated attacker with read-only privilege…EPSS 1.6%7.5CVE-2021-27857Fatpipeinc ipvpn firmware missing authorization vulnerabilityA missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 1…EPSS 1.8%5.3CVE-2021-27858Fatpipeinc ipvpn firmware missing authorization vulnerabilityA missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 1…EPSS 2.7%10.0CVE-2026-56291Balbooa Forms Joomla extension unauthenticated arbitrary file upload RCEThe Balbooa Forms extension for Joomla before version 2.4.1 accepts file uploads without authentication and does not restrict file type, allowing exe…KEVEPSS 15%analysed10.0CVE-2026-48939iCagenda Joomla extension unrestricted file upload leads to PHP RCEThe iCagenda extension for Joomla fails to restrict file types in its file attachment feature, allowing arbitrary file uploads that result in PHP cod…KEVEPSS 20%analysed10.0CVE-2026-56290Joomla Page Builder CK unauthenticated file upload leads to RCEThe Joomla Page Builder CK extension before 3.6.0 allows unauthenticated arbitrary file uploads, letting an attacker place executable files on the se…KEVEPSS 31%analysed

Source: NIST National Vulnerability Database (record CVE-2021-27860), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.