← Back to browse · API

CVE-2021-27860

Severity
CRITICAL
CVSS
9.8
EPSS
0.39824
Risk score
78.14
CISA KEV
Yes
PoC
No
Published
2022-01-10
Modified
2022-01-10
First seen
2026-08-07
Aliases
EUVD-2021-14598, GHSA-HFGW-XGJR-V384
Products
FatPipe:IPVPN 10.1 <10.1.2r60p92, FatPipe:IPVPN 10.2 <10.2.2r44p1, FatPipe:MPVPN 10.1 <10.1.2r60p92, FatPipe:MPVPN 10.2 <10.2.2r44p1, FatPipe:WARP 10.1 <10.1.2r60p92, FatPipe:WARP 10.2 <10.2.2r44p1, FatPipe:WARP, IPVPN, and MPVPN software
Sources
euvd EUVD-2021-14598
cisa.gov CVE-2021-27860

Description

A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthenticated attacker to upload a file to any location on the filesystem.

References