FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 contain a missing authorization caused by lack of access control in the web management interface, letting remote attackers access sensitive URLs, exploit requires no authentication.
id: CVE-2021-27858
info:
name: FatPipe WARP/IPVPN/MPVPN - Authorization Bypass
author: gy741
...