External risk intelligence

FatPipe OS Command Injection in xtremed Daemon

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-90822

The vulnerability affects a management interface that is disabled by default and requires manual configuration to enable. While it is network-reachable if enabled, standard deployment guidance emphasizes keeping such interfaces restricted to internal, trusted administrative networks, making public internet exposure uncommon in typical, secure deployments.

OS Command Injection

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in FatPipe appliances, specifically related to command injection within an older firmware version. While the affected management interface is typically disabled by default and requires explicit customer configuration to be accessible, its exploitation could allow an unauthenticated remote attacker to execute arbitrary commands with root privileges. The primary concern is to confirm whether this specific firmware and management interface configuration are in use within our environment.

  • Unauthenticated remote command execution risk.
  • Management interface requires explicit enabling.
  • Confirm relevance and exposure in our environment.

Attack Path

How an attacker could exploit the issue

An attacker could reach the vulnerable component by accessing the appliance's management interface, provided it has been enabled. This interface allows an unauthenticated remote attacker to submit specially crafted input to a specific endpoint. Successful manipulation of this endpoint can lead to arbitrary command execution with root privileges on the device.

  • Management interface must be enabled.
  • Crafted input sent to AuthFormServlet endpoint.
  • Arbitrary commands execute as root.

Live Threat

Current exploitation, exposure, and threat context

When the management interface is enabled, an unauthenticated remote attacker could execute arbitrary commands as the root user. This could impact system integrity and availability.

  • System commands could be executed.
  • Via an enabled management interface.
  • System integrity and availability may be affected.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts FatPipe appliances, likely managed by network or security teams responsible for appliance security and access control. The first step is to identify these appliances, confirm the firmware version, and verify if the management interface is enabled and exposed.

  • Network and security teams own the issue.
  • Verify management interface enablement and exposure.
  • Plan upgrade or access control remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is FatPipe MPVPN, WARP, and IPVPN?

These are networking appliances designed to provide wide area network (WAN) optimization, load balancing, and secure site-to-site connectivity. They function as critical infrastructure for managing data traffic across multiple connections. This specific vulnerability involves an older firmware component—the xtremed daemon—which handles background system processes and management tasks on these devices.

What does this CVE-2026-90822 vulnerability mean?

This is an OS command injection flaw (CWE-78). It means the device fails to properly sanitize input before processing it. Because the vulnerable service runs with root-level privileges, an attacker can bypass standard security controls to run their own unauthorized commands directly on the appliance’s underlying operating system.

How does an attacker trigger this bug?

An attacker triggers this by sending malicious input to the AuthFormServlet endpoint on the appliance. Crucially, the vulnerability cannot be triggered if the management interface is disabled, which is the default factory setting. The flaw only becomes reachable if a user has manually enabled this specific interface.

Do I need to worry about this if my device is internal?

According to Halo Surface Signal, this vulnerability is classified as 'Unlikely' because the affected interface is disabled by default. If you have enabled it, you should ensure it is restricted to a trusted, internal administrative network rather than the public internet. Access control lists are the primary way to prevent unauthorized remote reachability.

What should I do if I am running this technology?

First, verify your appliance's firmware version to see if it matches the affected release. If you are using that version, contact FatPipe support to coordinate an upgrade to a current, supported release. Simultaneously, audit your device configuration to confirm whether the management interface is currently enabled and ensure it is not accessible from untrusted networks.

References