Description
FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based buffer overflow in /usr/sbin/auth_user_pass. An unauthenticated remote attacker with access to the affected management interface can submit a crafted authentication request that reaches an unchecked copy into a fixed-size stack buffer, potentially allowing arbitrary code execution as root.

The affected management interface is disabled by default and must be affirmatively enabled by the customer before the endpoint becomes reachable. FatPipe recommends restricting management access to trusted administrative networks and using WAN access control lists to limit access to trusted sources.

Customers running the affected end-of-life firmware can contact FatPipe Support for help confirming their firmware version and upgrading to a current supported release at https://www.fatpipeinc.com/support/support, support@fatpipeinc.com, or +1 800-724-8521 (option 3).
Published: 2026-09-17
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A stack-based buffer overflow exists in the authentication handler for FatPipe MPVPN, WARP, and IPVPN appliances. An unauthenticated attacker who can reach the exposed management interface can send a specially crafted authentication request that overflows an unchecked stack buffer, giving the attacker arbitrary code execution with root privileges on the appliance. The vulnerability directly compromises confidentiality, integrity, and availability of the system.

Affected Systems

The affected products are FatPipe Networks IPVPN, MPVPN, and WARP appliances running end-of-life firmware version 10.1.2r60p100. Management interface access is disabled by default but must be enabled by the customer; once enabled, the interface becomes reachable for remote traffic.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity. Exploitability is high because no authentication is required and the vulnerable code resides in a commonly reachable management interface. Although a current EPSS value is not available, the lack of a KEV listing does not reduce the inherent risk. If an attacker gains network reach to the interface, the stack overflow can be triggered with a simple crafted request, leading to full system compromise.

Generated by OpenCVE AI on September 17, 2026 at 21:24 UTC.

Remediation

Vendor Solution

Customers running the affected end-of-life firmware should contact FatPipe Support to upgrade their appliances to the latest supported software release. The vulnerability has been addressed in current FatPipe software, and a remediated release is already available. As an interim mitigation pending the upgrade, leave the affected management interface disabled if it is not required, restrict management access to trusted administrative networks, use WAN access control lists to permit connections only from authorized source addresses, and avoid exposing the management interface directly to the public Internet.


OpenCVE Recommended Actions

  • Upgrade to the latest supported FatPipe firmware that contains the stack‑buffer overflow fix.
  • If an upgrade is not immediately possible, disable the management interface when it is not needed.
  • Restrict management access to trusted administrative networks and employ WAN access‑control lists that permit connections only from authorized source addresses.
  • Avoid exposing the management interface directly to the public Internet.

Generated by OpenCVE AI on September 17, 2026 at 21:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Fatpipe Networks
Fatpipe Networks ipvpn
Fatpipe Networks mpvpn
Fatpipe Networks warp
Vendors & Products Fatpipe Networks
Fatpipe Networks ipvpn
Fatpipe Networks mpvpn
Fatpipe Networks warp

Thu, 17 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Stack-Based Buffer Overflow in FatPipe Management Interface Allows Remote Code Execution

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based buffer overflow in /usr/sbin/auth_user_pass. An unauthenticated remote attacker with access to the affected management interface can submit a crafted authentication request that reaches an unchecked copy into a fixed-size stack buffer, potentially allowing arbitrary code execution as root. The affected management interface is disabled by default and must be affirmatively enabled by the customer before the endpoint becomes reachable. FatPipe recommends restricting management access to trusted administrative networks and using WAN access control lists to limit access to trusted sources. FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based buffer overflow in /usr/sbin/auth_user_pass. An unauthenticated remote attacker with access to the affected management interface can submit a crafted authentication request that reaches an unchecked copy into a fixed-size stack buffer, potentially allowing arbitrary code execution as root. The affected management interface is disabled by default and must be affirmatively enabled by the customer before the endpoint becomes reachable. FatPipe recommends restricting management access to trusted administrative networks and using WAN access control lists to limit access to trusted sources. Customers running the affected end-of-life firmware can contact FatPipe Support for help confirming their firmware version and upgrading to a current supported release at https://www.fatpipeinc.com/support/support, support@fatpipeinc.com, or +1 800-724-8521 (option 3).
References

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Description FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based buffer overflow in /usr/sbin/auth_user_pass. An unauthenticated remote attacker with access to the affected management interface can submit a crafted authentication request that reaches an unchecked copy into a fixed-size stack buffer, potentially allowing arbitrary code execution as root. The affected management interface is disabled by default and must be affirmatively enabled by the customer before the endpoint becomes reachable. FatPipe recommends restricting management access to trusted administrative networks and using WAN access control lists to limit access to trusted sources.
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Fatpipe Networks Ipvpn Mpvpn Warp
cve-icon MITRE

Status: PUBLISHED

Assigner: Securifera

Published:

Updated: 2026-09-17T14:10:27.493Z

Reserved: 2026-09-13T19:10:47.080Z

Link: CVE-2026-90823

cve-icon Vulnrichment

Updated: 2026-09-17T14:08:51.260Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T12:18:28.843

Modified: 2026-09-18T19:25:29.923

Link: CVE-2026-90823

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:02:37Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow