Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-90823: FatPipe MPVPN, WARP, IPVPN allow remote code execution

CVE-2026-90823 · published 9 days ago
Summary

The management interface on FatPipe MPVPN, WARP, and IPVPN devices running the old 10.1.2r60p100 firmware can be tricked into running any code an attacker sends, giving them full control of the device. This only happens if the management interface has been turned on, which is off by default, but it should be limited to trusted networks and protected with access lists. Update the firmware to a supported version as soon as possible; contact FatPipe support for help verifying the version and applying the upgrade.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
fatpipe networks mpvpn 10.1.2r60p100
fatpipe networks warp 10.1.2r60p100
fatpipe networks ipvpn 10.1.2r60p100
Original advisory text
FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based buffer overflow in /usr/sbin/auth_user_pass. An unauthenticated remote attacke...
FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based buffer overflow in /usr/sbin/auth_user_pass. An unauthenticated remote attacker with access to the affected management interface can submit a crafted authentication request that reaches an unchecked copy into a fixed-size stack buffer, potentially allowing arbitrary code execution as root.

The affected management interface is disabled by default and must be affirmatively enabled by the customer before the endpoint becomes reachable. FatPipe recommends restricting management access to trusted administrative networks and using WAN access control lists to limit access to trusted sources.

Customers running the affected end-of-life firmware can contact FatPipe Support for help confirming their firmware version and upgrading to a current supported release at https://www.fatpipeinc.com/support/support, [email protected], or +1 800-724-8521 (option 3).
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-121Stack-based Buffer Overflow
Timeline
Published17 Sep 2026
Updated26 Sep 2026
First seen17 Sep 2026
Sources
CVE-2026-90823 · MITRE
Track software like this
Free during beta