Fatpipeinc develops a focused line of network optimization and SD-WAN appliances, including the IPVPN and MPVPN product families and the Warp platform, that sit in critical positions within enterprise network infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, a strong history of confirmed in-the-wild exploitation, and frequent public exploit availability. The recurring exposure centers on authorization bypass, unrestricted file uploads, and related access-control issues that are endemic to remotely managed appliances, making prompt patching essential for defenders managing these devices. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fatpipeinc over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27860HIGH A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker | Dec 8, 2021 | 8.8 | 84 | YES | NO |
CVE-2021-27856CRITICAL FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 includes an account named "cmuser" that has administrative privileges and no password. Older ve | Dec 15, 2021 | 9.8 | 43 | NO | YES |
CVE-2021-27858MEDIUM A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote attack | Dec 15, 2021 | 5.3 | 30 | NO | YES |
CVE-2021-27859HIGH A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows an authenticate | Dec 15, 2021 | 8.8 | 28 | NO | NO |
CVE-2021-27855HIGH FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote, authenticated attacker with read-only privileges to grant themselves administr | Dec 15, 2021 | 8.8 | 28 | NO | NO |
CVE-2021-27857HIGH A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote, unaut | Dec 15, 2021 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fatpipeinc.
Media articles that mention a CVE ID that affects a product developed by Fatpipeinc — matched by CVE ID, not by vendor name.