What is FatPipe MPVPN/WARP/IPVPN?
FatPipe Networks produces WAN optimization and SD-WAN appliances — specifically WARP (WAN Redundancy and Aggregation), IPVPN (IP VPN aggregation), and MPVPN (multi-path VPN) products. These are enterprise networking appliances that aggregate multiple WAN links (e.g., multiple ISP connections) to provide redundant, load-balanced internet connectivity. As internet-facing network appliances, they have web-based management interfaces accessible from the network — and vulnerabilities in these interfaces can provide unauthenticated access to network infrastructure.
Overview
CVE-2021-27860 is an unauthenticated arbitrary file upload vulnerability (CWE-434) in the web management interface of FatPipe WARP, IPVPN, and MPVPN devices. A remote, unauthenticated attacker can upload files to any location on the filesystem. By uploading a webshell to a web-accessible directory, an attacker achieves arbitrary code execution with root privileges on the appliance. The FBI issued a Flash Alert (MU-000167-MW) in November 2021 warning that APT actors had exploited this to gain root access and install webshells on FatPipe devices, using them as pivot points into corporate networks.
Affected Versions
| Product | Vulnerable | Fixed |
|---|---|---|
| FatPipe MPVPN | < 10.1.2r60p93 / < 10.2.2r44p1 | 10.1.2r60p93, 10.2.2r44p1 |
| FatPipe WARP | Corresponding versions | Corresponding fix |
| FatPipe IPVPN | Corresponding versions | Corresponding fix |
Technical Details
The FatPipe web management interface provides a file upload endpoint for configuration and firmware updates. This endpoint lacks proper authentication enforcement, allowing any network-accessible client to upload files without presenting credentials:
- Root cause: Missing authentication check on the file upload endpoint (CWE-434 — unrestricted upload of file with dangerous type)
- File placement: The attacker can specify an arbitrary path on the filesystem for the uploaded file
- Webshell deployment: Uploading a PHP or Perl webshell to a web-accessible directory (e.g., the web server document root) provides interactive code execution via HTTP
- Execution context: Commands execute as root on the appliance's Linux-based OS
- APT exploitation: The FBI Flash Alert documented APT actors using this for persistent access: installing webshells, maintaining root-level footholds, and using the compromised appliance as a staging point for lateral movement
Discovery
Identified by FatPipe and reported via security advisory. The FBI's Flash Alert (preceding the formal CVE publication) indicates the FBI was investigating active APT exploitation of this vulnerability before FatPipe published the patch.
Exploitation Context
APT actors used CVE-2021-27860 to establish persistent footholds on enterprise network infrastructure. By compromising a FatPipe WAN aggregation device, adversaries gained a position on the network perimeter that provides visibility into traffic and a pivot point for accessing internal networks. The FBI Flash Alert noted exploitation as far back as May 2021 — months before the advisory — indicating sophisticated actors had prior knowledge of the vulnerability and exploited it as a zero-day.
Remediation
- Upgrade FatPipe MPVPN to 10.1.2r60p93 or 10.2.2r44p1 or later; apply corresponding patches for WARP and IPVPN
- Check for webshells before assuming patching is sufficient — search for unexpected PHP/Perl files in web-accessible directories on the appliance
- Restrict access to the FatPipe web management interface to trusted management IPs only; it should not be exposed to the internet
- Review FatPipe web access logs for unexpected file upload requests, especially to sensitive paths
- If compromise is confirmed, consider factory reset and fresh configuration rather than just patching over a compromised appliance
- Implement network segmentation so compromise of the WAN aggregation device does not immediately expose the full internal network
Key Details
| Property | Value |
|---|---|
| CVE ID | CVE-2021-27860 |
| Vendor / Product | FatPipe — WARP, IPVPN, and MPVPN software |
| NVD Published | 2021-12-08 |
| NVD Last Modified | 2025-10-24 |
| CVSS 3.1 Score | 9.8 |
| CVSS 3.1 Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Severity | CRITICAL |
| CWE | CWE-434 find similar ↗ |
| CISA KEV Added | 2022-01-10 |
| CISA KEV Deadline | 2022-01-24 |
| Known Ransomware Use | No |
CVSS 3.1 Breakdown
Required Action
Timeline
| Date | Event |
|---|---|
| 2021-11-17 | FBI releases Flash Alert MU-000167-MW on APT exploitation of CVE-2021-27860 |
| 2021-12-08 | FatPipe publishes security advisory; CVE published |
| 2022-01-10 | Added to CISA Known Exploited Vulnerabilities catalog |
| 2022-01-24 | CISA BOD 22-01 remediation deadline |
References
| Resource | Type |
|---|---|
| FatPipe Security Advisory FP-2021-02-01 | Vendor Advisory |
| FBI Flash Alert MU-000167-MW — APT Exploitation of FatPipe MPVPN | US Government |
| NVD — CVE-2021-27860 | Vulnerability Database |
| CISA KEV Catalog Entry | US Government |