S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Oct 8, 2025

CVE-2021-27858 Scanner

CVE-2021-27858 Scanner - Missing Authorization vulnerability in FatPipe WARP/IPVPN/MPVPN

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.2k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-27858
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote attacker to access at least the URL "/fpui/jsp/index.jsp" leading to unknown impact, presumably some violation of confidentiality. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory identifier for this vulnerability is FPSA004.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WARPby FatPipe
AFFECTED< 10.1.2r60p91SAFE ✓≥ 10.1.2r60p91
IPVPNby FatPipe
AFFECTED< 10.1.2r60p91SAFE ✓≥ 10.1.2r60p91
MPVPNby FatPipe
AFFECTED< 10.1.2r60p91SAFE ✓≥ 10.1.2r60p91
Updated Aug 21, 2026View on NVD →
Detail

FatPipe WARP/IPVPN/MPVPN is widely used in enterprise environments for secure and efficient WAN traffic management. These products are primarily employed by businesses requiring enhanced bandwidth management and secure Internet connectivity. With features like dynamic and static load balancing and route plans, they optimize VPN performance across multiple links. IT departments across various sectors utilize them due to their scalability and reliability, crucial for maintaining operational continuity. As such, any vulnerability in these products can pose significant risks to enterprise network security and operations.

The Missing Authorization vulnerability in FatPipe WARP/IPVPN/MPVPN allows unauthorized access to sensitive URLs via the web management interface. This lack of proper access control can be exploited by remote attackers to access or manipulate sensitive information. Its ease of exploitation without needing prior authentication makes it particularly dangerous. This vulnerability highlights the critical need for rigorous authorization validation within web management systems of network appliances. Organizations using affected versions might unknowingly expose sensitive network configurations to malicious actors.

The technical specifics of this vulnerability involve missing access controls within the FatPipe WARP/IPVPN/MPVPN's web management interface. Remote attackers can leverage this flaw to request URLs that should be protected, leading to potential exposure of sensitive data or network settings. The exploitation of this vulnerability requires no authentication, allowing attackers easy entry. This is particularly concerning in enterprise environments where such access could compromise overall network security. Examination of requests to '/fpui/jsp/index.jsp' can reveal this authorization lapse.

Exploiting this vulnerability could lead to unauthorized disclosure of network configurations impacting the organization's security posture. Attackers may gain insights or make unauthorized changes to the routing setup, affecting traffic flow or enabling further exploits. The confidentiality of strategic business data could be at risk, given the potential access to sensitive management interfaces. Additionally, system integrity may be compromised, impacting organizational operations.

REFERENCES

Solution Advice
  • Apply the latest software updates to FatPipe products to mitigate known vulnerabilities.
  • Implement a comprehensive access control strategy limiting access to the web management interface.
  • Regularly audit network appliance configurations for unauthorized changes or signs of exploit attempts.
  • Monitor network traffic for anomalous behaviors, especially concerning management interfaces.
  • Provide regular security training to administrators on managing network appliance security effectively.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-27858 Scanner - Missing Authorization vulnerability in FatPipe WARP/IPVPN/MPVPN | S4E