Two unauthenticated root RCEs hit FatPipe’s end-of-life appliances
FatPipe MPVPN, WARP and IPVPN appliances on the end-of-life 10.1.2r60p100 firmware expose an OS command injection and a stack buffer overflow that both yield an unauthenticated root shell. Move to a supported release and lock down the management interface, which ships disabled by default.