Stack-Based Buffer Overflow in FatPipe MPVPN, WARP, and IPVPN Appliances
CVE-2026-90823

9.8CRITICAL

Key Information:

Vendor
CVE Published:
17 September 2026

What is CVE-2026-90823?

FatPipe MPVPN, WARP, and IPVPN appliances utilizing the end-of-life firmware version 10.1.2r60p100 are vulnerable to a stack-based buffer overflow in the /usr/sbin/auth_user_pass component. An unauthenticated remote attacker can exploit this vulnerability by submitting a crafted authentication request through the affected management interface. If left enabled, this could lead to arbitrary code execution with root privileges, posing significant risks to system integrity. Although the management interface is off by default, it’s vital for users to restrict access to authorized administrative networks and implement WAN access control lists to mitigate potential exploitation.

Affected Version(s)

IPVPN 10.1.2r60p100

MPVPN 10.1.2r60p100

WARP 10.1.2r60p100

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ryan Wincey (@rwincey, Securifera)
.