Impact
An OS command‑injection flaw in the xtremed daemon allows a remote attacker to send crafted input to the AuthFormServlet endpoint of the management interface. When the interface is enabled, the firmware processes this data through a shell, giving the attacker arbitrary command execution with root privileges. The flaw is silent unless the interface is reachable, but once accessed it can compromise the entire appliance
Affected Systems
FatPipe Networks appliances – IPVPN, MPVPN, and WARP – running the end‑of‑life firmware version 10.1.2r60p100 are affected. The management interface is disabled by default and must be explicitly enabled by the customer before the endpoint becomes reachable
Risk and Exploitability
The CVSS score of 9.8 marks this vulnerability as critical. The EPSS score is 1%, and the issue is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability remotely without authentication if the management interface is exposed or improperly restricted, making the risk high for any deployment that has the interface accessible from untrusted networks
OpenCVE Enrichment