← Back to CVE List
Vulnerability Intelligence Report

CVE-2026-90823

FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based buffer overflow in /usr/sbin/auth_user_pass. An unauthenticated remote attacker with access to the affected management interface can submit a crafted authentication request that reaches an unchecked copy into a fixed-size stack buffer, potentially allowing arbitrary code execution as root. The affected management interface is disabled by default and must be affirmatively enabled by the customer before the endpoint becomes reachable. FatPipe recommends restricting management access to trusted administrative networks and using WAN access control lists to limit access to trusted sources. Customers running the affected end-of-life firmware can contact FatPipe Support for help confirming their firmware version and upgrading to a current supported release at https://www.fatpipeinc.com/support/support, support@fatpipeinc.com, or +1 800-724-8521 (option 3).

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-121 ↗CWE-121: Stack-based Buffer Overflow

Affected Products & Versions

Vendor Product Affected Versions
FatPipe Networks MPVPN 10.1.2r60p100 (affected)
FatPipe Networks WARP 10.1.2r60p100 (affected)
FatPipe Networks IPVPN 10.1.2r60p100 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Identity & Timeline

StatusPUBLISHED
Assigning AuthoritySecurifera, Inc. · Researcher · USA
Reserved2026-09-13T19:10:47
Published2026-09-17T11:57:54
Last Updated2026-09-17T14:10:27

LINK COPIED TO CLIPBOARD