CVE-2021-27860 is a critical vulnerability affecting the web management interface of FatPipe WARP, IPVPN, and MPVPN software versions prior to 10.1.2r60p92 and 10.2.2r44p1. This flaw, categorized as CWE-434 (Unrestricted Upload of File with Dangerous Type), allows an unauthenticated, remote attacker to upload arbitrary files to any location on the affected system. With a CVSS score of 8.8 (HIGH), the vulnerability poses a significant risk, enabling potential complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog, and has garnered substantial community discussion and media coverage, despite no public Metasploit or ExploitDB modules.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.2.0CPE matchmatch criteria | cpe:2.3:o:fatpipeinc:ipvpn_firmware:5.2.0:r34:*:*:*:*:*:* | ||
6.1.2CPE matchmatch criteria | cpe:2.3:o:fatpipeinc:ipvpn_firmware:6.1.2:r70p26:*:*:*:*:*:* | ||
6.1.2CPE matchmatch criteria | cpe:2.3:o:fatpipeinc:ipvpn_firmware:6.1.2:r70p45-m:*:*:*:*:*:* | ||
6.1.2CPE matchmatch criteria | cpe:2.3:o:fatpipeinc:ipvpn_firmware:6.1.2:r70p75-m:*:*:*:*:*:* | ||
7.1.2CPE matchmatch criteria | cpe:2.3:o:fatpipeinc:ipvpn_firmware:7.1.2:r39:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.