Description
FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command injection vulnerability in the xtremed daemon. An unauthenticated remote attacker with access to the affected management interface can submit crafted input to the AuthFormServlet endpoint, causing authentication data to be processed by a shell and allowing arbitrary commands to execute as root.

The affected management interface is disabled by default and must be affirmatively enabled by the customer before the endpoint becomes reachable. FatPipe recommends restricting management access to trusted administrative networks and using WAN access control lists to limit access to trusted sources.

Customers running the affected end-of-life firmware can contact FatPipe Support for help confirming their firmware version and upgrading to a current supported release at https://www.fatpipeinc.com/support/support, support@fatpipeinc.com, or +1 800-724-8521 (option 3).
Published: 2026-09-17
Score: 9.8 Critical
EPSS: 1.4% Low
KEV: No
Impact: Remote code execution as root via unauthenticated access to a custom management endpoint
Action: Patch Now
AI Analysis

Impact

An OS command‑injection flaw in the xtremed daemon allows a remote attacker to send crafted input to the AuthFormServlet endpoint of the management interface. When the interface is enabled, the firmware processes this data through a shell, giving the attacker arbitrary command execution with root privileges. The flaw is silent unless the interface is reachable, but once accessed it can compromise the entire appliance

Affected Systems

FatPipe Networks appliances – IPVPN, MPVPN, and WARP – running the end‑of‑life firmware version 10.1.2r60p100 are affected. The management interface is disabled by default and must be explicitly enabled by the customer before the endpoint becomes reachable

Risk and Exploitability

The CVSS score of 9.8 marks this vulnerability as critical. The EPSS score is 1%, and the issue is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability remotely without authentication if the management interface is exposed or improperly restricted, making the risk high for any deployment that has the interface accessible from untrusted networks

Generated by OpenCVE AI on September 20, 2026 at 04:54 UTC.

Remediation

Vendor Solution

Customers running the affected end-of-life firmware should contact FatPipe Support to upgrade their appliances to the latest supported software release. The vulnerability has been addressed in current FatPipe software, and a remediated release is already available. As an interim mitigation pending the upgrade, leave the affected management interface disabled if it is not required, restrict management access to trusted administrative networks, use WAN access control lists to permit connections only from authorized source addresses, and avoid exposing the management interface directly to the public Internet.


OpenCVE Recommended Actions

  • Upgrade the appliance firmware to the latest supported release
  • If the management interface is not required, leave it disabled
  • If the interface must be enabled, restrict management access to trusted administrative networks, using WAN access control lists to permit connections only from authorized source addresses, and avoid exposing the management interface to the public Internet

Generated by OpenCVE AI on September 20, 2026 at 04:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Title Root Command Execution via Authentication Endpoint in FatPipe Management Interface

Thu, 17 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Root Command Execution via Authentication Endpoint in FatPipe Management Interface

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Fatpipe Networks
Fatpipe Networks ipvpn
Fatpipe Networks mpvpn
Fatpipe Networks warp
Vendors & Products Fatpipe Networks
Fatpipe Networks ipvpn
Fatpipe Networks mpvpn
Fatpipe Networks warp

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command injection vulnerability in the xtremed daemon. An unauthenticated remote attacker with access to the affected management interface can submit crafted input to the AuthFormServlet endpoint, causing authentication data to be processed by a shell and allowing arbitrary commands to execute as root. The affected management interface is disabled by default and must be affirmatively enabled by the customer before the endpoint becomes reachable. FatPipe recommends restricting management access to trusted administrative networks and using WAN access control lists to limit access to trusted sources. FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command injection vulnerability in the xtremed daemon. An unauthenticated remote attacker with access to the affected management interface can submit crafted input to the AuthFormServlet endpoint, causing authentication data to be processed by a shell and allowing arbitrary commands to execute as root. The affected management interface is disabled by default and must be affirmatively enabled by the customer before the endpoint becomes reachable. FatPipe recommends restricting management access to trusted administrative networks and using WAN access control lists to limit access to trusted sources. Customers running the affected end-of-life firmware can contact FatPipe Support for help confirming their firmware version and upgrading to a current supported release at https://www.fatpipeinc.com/support/support, support@fatpipeinc.com, or +1 800-724-8521 (option 3).
References

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Description FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command injection vulnerability in the xtremed daemon. An unauthenticated remote attacker with access to the affected management interface can submit crafted input to the AuthFormServlet endpoint, causing authentication data to be processed by a shell and allowing arbitrary commands to execute as root. The affected management interface is disabled by default and must be affirmatively enabled by the customer before the endpoint becomes reachable. FatPipe recommends restricting management access to trusted administrative networks and using WAN access control lists to limit access to trusted sources.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Fatpipe Networks Ipvpn Mpvpn Warp
cve-icon MITRE

Status: PUBLISHED

Assigner: Securifera

Published:

Updated: 2026-09-17T14:15:14.007Z

Reserved: 2026-09-13T19:10:47.079Z

Link: CVE-2026-90822

cve-icon Vulnrichment

Updated: 2026-09-17T14:15:09.903Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T12:18:28.713

Modified: 2026-09-18T19:25:29.923

Link: CVE-2026-90822

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:00:13Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')