CVE-2026-90822 Details
Description
FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command injection vulnerability in the xtremed daemon. An unauthenticated remote attacker with access to the affected management interface can submit crafted input to the AuthFormServlet endpoint, causing authentication data to be processed by a shell and allowing arbitrary commands to execute as root. The affected management interface is disabled by default and must be affirmatively enabled by the customer before the endpoint becomes reachable. FatPipe recommends restricting management access to trusted administrative networks and using WAN access control lists to limit access to trusted sources. Customers running the affected end-of-life firmware can contact FatPipe Support for help confirming their firmware version and upgrading to a current supported release at https://www.fatpipeinc.com/support/support, [email protected], or +1 800-724-8521 (option 3).
A remote command injection vulnerability has been identified in FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100. The vulnerability resides in the xtremed daemon, where an unauthenticated remote attacker with access to the management interface can send crafted input to the AuthFormServlet endpoint. This input is then processed by a shell, allowing arbitrary commands to be executed as root. Although the vulnerable management interface is disabled by default, it can be enabled by the customer, making the endpoint accessible.
Customers running the affected firmware version can contact FatPipe Support to confirm their firmware version and upgrade to a current supported release. FatPipe recommends restricting management access to trusted administrative networks and using WAN access control lists to limit access to trusted sources.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 17, 2026CISA-ADP
Assessed Sep 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.fatpipeinc.com/support/support | [email protected] | Vendor |
| https://www.securifera.com/advisories/ | [email protected] | AdvisoryBundle |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| FatPipe MPVPN | 10.1.2r60p100 |
CPE
Remediation
| |
| FatPipe WARP | 10.1.2r60p100 |
CPE
Remediation
| |
| FatPipe IPVPN | 10.1.2r60p100 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | CVE Modified | CISA-ADP |
| Sep 17, 2026 | CVE Modified | [email protected] |
| Sep 17, 2026 | New CVE Received | [email protected] |
Volerion