Sceawere

Vulnerability Detail

CVE-2026-90822UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

FatPipe OS Command Injection

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
9h ago
Vendor
Product
N/A
Attack Type
N/A
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Narrative and Response

Description

FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command injection vulnerability in the xtremed daemon. An unauthenticated remote attacker with access to the affected management interface can submit crafted input to the AuthFormServlet endpoint, causing authentication data to be processed by a shell and allowing arbitrary commands to execute as root. The affected management interface is disabled by default and must be affirmatively enabled by the customer before the endpoint becomes reachable. FatPipe recommends restricting management access to trusted administrative networks and using WAN access control lists to limit access to trusted sources. Customers running the affected end-of-life firmware can contact FatPipe Support for help confirming their firmware version and upgrading to a current supported release at https://www.fatpipeinc.com/support/support, support@fatpipeinc.com, or +1 800-724-8521 (option 3).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-09-17T12:18:28.713Z",
  "pubdate": "2026-09-17T12:18:28.713Z",
  "executiveSummary": "FatPipe MPVPN, WARP, and IPVPN appliances running firmware version 10.1.2r60p100 are susceptible to an OS command injection vulnerability located within the xtremed daemon.\nThe vulnerability resides in the AuthFormServlet endpoint, which improperly sanitizes user-supplied authentication data before passing it to the system shell for processing.\nAn unauthenticated remote attacker capable of reaching the management interface can leverage this flaw to achieve arbitrary command execution with root-level privileges.\nWhile the management interface is disabled by default, the risk remains significant for organizations that have enabled remote management access, as this oversight allows for full system compromise.\nSuccessful exploitation permits total control over the appliance, potentially leading to unauthorized data access, network interception, or complete system takeover by the attacker.",
  "technicalDetails": "The vulnerability exists within the xtremed daemon, specifically in the processing logic of the AuthFormServlet endpoint. The issue is classified as an OS command injection flaw, where the appliance fails to perform adequate input validation or sanitization on data submitted to the authentication form.\nWhen an unauthenticated request is sent to the AuthFormServlet endpoint, the xtremed daemon processes the supplied authentication parameters. Because the application insecurely passes these user-controlled inputs to a system shell, an attacker can append malicious commands to the expected input parameters. This allows for the execution of arbitrary shell commands within the context of the root user.\nThe exploitation flow begins with the attacker identifying a reachable management interface on the target FatPipe device. Because the service is not enabled by default, the attacker relies on the appliance owner having previously activated this interface. The attacker then crafts an HTTP request targeting the AuthFormServlet endpoint, injecting shell metacharacters such as ';', '|', or '&&' along with the intended payload. The backend shell, executing on behalf of the xtremed daemon, processes the manipulated string as a sequence of commands rather than treating the input as literal authentication credentials.\nBecause the xtremed daemon operates with root-level permissions, the injected commands are executed with elevated system privileges. This grants the attacker unrestricted access to the underlying operating system. The attacker can then deploy persistent backdoors, extract sensitive configuration files, modify network routing tables, or use the device as a pivot point for further lateral movement within the enterprise network.\nThe affected firmware version is specifically identified as 10.1.2r60p100. Given that this is an end-of-life firmware version, the lack of robust input filtering reflects a broader security posture issue in legacy codebases. The vulnerability highlights the critical importance of secure coding practices when handling external user input in network-exposed management services."
}
CVE-2026-90822: FatPipe OS Command Injection (CRITICAL Severity, CVSS: 9.8) | Sceawere