Zero-day VPN software flaw exploited by APT hackers

Representational image depecting cybersecurity protection
(Image credit: Shutterstock)

An advanced persistent threat (APT) group has been actively exploiting a zero-day flaw in FatPipe’s software that powers its virtual private networking (VPN) devices,  the FBI has warned.

While the FBI hasn’t shared details about the attackers, its cybersecurity sleuths have discovered that the group has been using the flaw since at least May 2021.

“The vulnerability allowed APT actors to gain access to an unrestricted file upload function to drop a webshell for exploitation activity with root access, leading to elevated privileges and potential follow-on activity,” notes the FBI in its advisory.

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

Interestingly, analysis of the group’s activity has shown that the threat actors took various steps to cover evidence of their break-in, including wiping their session activity to avoid detection.

Patch now

According to the FBI, the bug hasn’t yet been assigned a CVE number, but has been fixed by FatPipe.

Explaining the bug in its own advisory, FatPipe notes that it exists in the software’s web management interface.

“The vulnerability is due to a lack of input and validation checking mechanisms for certain HTTP requests on an affected device. An attacker could exploit this vulnerability by sending a modified HTTP request to the affected device,” explains FatPipe.

The vulnerability affects all FatPipe WARP, MPVPN, and IPVPN device software prior to the latest version releases, 10.1.2r60p93 and 10.2.2r44p1. Since there aren’t any known workarounds to the bug, both the FBI and FatPipe urge users to upgrade to the latest patched release without delay. 

If you are concerned about online privacy, use one of the best business VPN services

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
vpn
Ivanti warns another critical security flaw is being attacked
A person at a laptop with a cybersecure lock symbol floating above it.
Hackers are still using old Ivanti bugs to break into networks
Best free Linux firewalls
Fortinet warns a critical vulnerability in its systems could let attackers breach company networks
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
China-linked cyberespionage group PlushDaemon used South Korean VPN service to inject malware
Representational image depecting cybersecurity protection
Hackers are breaking SonicWall products to target business networks
The best free firewall
Palo Alto warns another major firewall hack has been detected
Latest in VPN Privacy & Security
A stethoscope next to a laptop on a pink background
How to check if your VPN is working
Teenager playing on a gaming PC with two monitors
Is using a VPN while gaming cheating? 5 myths you shouldn't believe about gaming with a VPN
Neon blue email symbols on a black background
Why am I suddenly getting so many spam emails?
A computer file surrounded by red laser beams
Cover your tracks: the risk of sending unencrypted files
Using an Amazon Fire Stick on a Smart TV
How to use a VPN with Fire Stick
Close up of PS5 DualSense controller leaning on a PS5
5 reasons your PS5 needs a VPN
Latest in News
Seth Milchick and Kier Eagan&#039;s animatronic speaking in Severance season 2 episode 10
Apple TV+ announces Severance has been renewed for season 3 after that devastating finale
Spotify&#039;s new Concerts Near You playlist feature showing a list of songs by local touring artists
Spotify has launched a new Concerts Near You playlist, making it easier for you to see if your favorite artists are performing in your area
The new Dr. Squatch Call of Duty collection.
Latest Call of Duty collaboration finally lets you rub your body with Soap - and I can't believe I just wrote that
Nanoleaf PC Screen Mirror Lightstrip set up on gaming PC
This Nanoleaf light strip adds Ambilight-style illumination to your gaming setup – and it's amazingly cheap
The Samsung Galaxy S21 series of phones lying face down.
Samsung announces One UI 7 is coming to older phones after all, but the launch is still a mess
Using Zipped files and folders in Windows 11
Windows 11 should soon be faster at extracting files from compressed ZIPs – and it’s about time, frankly