Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-90822: FatPipe MPVPN, WARP, IPVPN allow remote command execution

CVE-2026-90822 · published 9 days ago
Summary

The MPVPN, WARP and IPVPN appliances that are still running the old 10.1.2r60p100 firmware let an unauthenticated attacker send specially crafted data to the management interface and run any command as the system’s administrator. The management interface is off by default, but if you have enabled it, restrict its access to trusted networks and upgrade the firmware to a supported version as soon as possible. Contact FatPipe support for help confirming your version and obtaining the update.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
fatpipe networks mpvpn 10.1.2r60p100
fatpipe networks warp 10.1.2r60p100
fatpipe networks ipvpn 10.1.2r60p100
Original advisory text
FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command injection vulnerability in the xtremed daemon. An unauthenticated remote attac...
FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command injection vulnerability in the xtremed daemon. An unauthenticated remote attacker with access to the affected management interface can submit crafted input to the AuthFormServlet endpoint, causing authentication data to be processed by a shell and allowing arbitrary commands to execute as root.

The affected management interface is disabled by default and must be affirmatively enabled by the customer before the endpoint becomes reachable. FatPipe recommends restricting management access to trusted administrative networks and using WAN access control lists to limit access to trusted sources.

Customers running the affected end-of-life firmware can contact FatPipe Support for help confirming their firmware version and upgrading to a current supported release at https://www.fatpipeinc.com/support/support, [email protected], or +1 800-724-8521 (option 3).
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS 1%
Type
CWE-78OS Command Injection
Timeline
Published17 Sep 2026
Updated26 Sep 2026
First seen17 Sep 2026
Sources
CVE-2026-90822 · MITRE
Track software like this
Free during beta