Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-27858 PoC — FatPipe 安全漏洞

Source
Associated Vulnerability
Title:FatPipe 安全漏洞 (CVE-2021-27858)
Description:FatPipe是美国FatPipe公司的一种 WAN 冗余技术,它为公司提供自动和动态故障转移,因为广域网组件或服务故障导致数据线连接中断。 FatPipe WARP, IPVPN和MPVPN 10.1.2r60p91 和 10.2.2r42之前版本存在安全漏洞,该漏洞源于软件的web管理界面中缺少授权。攻击者可利用该漏洞访问URL“/fpui/jsp/index.jsp”,从而导致未知影响,可能违反了保密性。
Description
FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 contain a missing authorization caused by lack of access control in the web management interface, letting remote attackers access sensitive URLs, exploit requires no authentication.
File Snapshot

id: CVE-2021-27858 info: name: FatPipe WARP/IPVPN/MPVPN - Authorization Bypass author: gy741 ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.