Impact
A stack-based buffer overflow exists in the authentication handler for FatPipe MPVPN, WARP, and IPVPN appliances. An unauthenticated attacker who can reach the exposed management interface can send a specially crafted authentication request that overflows an unchecked stack buffer, giving the attacker arbitrary code execution with root privileges on the appliance. The vulnerability directly compromises confidentiality, integrity, and availability of the system.
Affected Systems
The affected products are FatPipe Networks IPVPN, MPVPN, and WARP appliances running end-of-life firmware version 10.1.2r60p100. Management interface access is disabled by default but must be enabled by the customer; once enabled, the interface becomes reachable for remote traffic.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. Exploitability is high because no authentication is required and the vulnerable code resides in a commonly reachable management interface. Although a current EPSS value is not available, the lack of a KEV listing does not reduce the inherent risk. If an attacker gains network reach to the interface, the stack overflow can be triggered with a simple crafted request, leading to full system compromise.
OpenCVE Enrichment