FatPipe WARP, IPVPN, and MPVPN software prior to versions...
        
  Critical severity
        
          Unreviewed
      
        Published
          Dec 16, 2021 
          to the GitHub Advisory Database
          •
          Updated Jan 27, 2023 
      
  
Description
        Published by the National Vulnerability Database
      Dec 15, 2021 
    
  
        Published to the GitHub Advisory Database
      Dec 16, 2021 
    
  
        Last updated
      Jan 27, 2023 
    
  
FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 includes an account named "cmuser" that has administrative privileges and no password. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory identifier for this vulnerability is FPSA002.
References