FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based buffer overflow in /usr/sbin/auth_user_pass. An unauthenticated remote attacker with access to the affected management interface can submit a crafted authentication request that reaches an unchecked copy into a fixed-size stack buffer, potentially allowing arbitrary code execution as root. The affected management interface is disabled by default and must be affirmatively enabled by the customer before the endpoint becomes reachable. FatPipe recommends restricting management access to trusted administrative networks and using WAN access control lists to limit access to trusted sources. Customers running the affected end-of-life firmware can contact FatPipe Support for help confirming their firmware version and upgrading to a current supported release at https://www.fatpipeinc.com/support/support, support@fatpipeinc.com, or +1 800-724-8521 (option 3).
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-90823 is a critical stack-based buffer overflow vulnerability (CWE-121) affecting FatPipe MPVPN, WARP, and IPVPN appliances running end-of-life firmware 10.1.2r60p100. The vulnerability exists in the /usr/sbin/auth_user_pass binary where an unchecked copy operation allows unauthenticated remote attackers to overflow a fixed-size stack buffer via crafted authentication requests sent to the management interface. While the management interface is disabled by default, organizations that have enabled it for remote administration face severe risk—successful exploitation grants arbitrary code execution with root privileges, potentially compromising the entire VPN infrastructure and all connected networks. This affects organizations relying on legacy FatPipe appliances for enterprise VPN connectivity and remote access.
Although Casky.ai currently has zero mapped skills directly addressing this specific CVE, Claude's extended reasoning capabilities can identify the attack surface and exploitation patterns associated with stack-based buffer overflow techniques. Practitioners using Casky would observe findings related to unauthenticated remote code execution attempts targeting management interfaces, abnormal memory access patterns in authentication processes, and potential privilege escalation indicators. Security teams should prioritize firmware upgrades to patched versions and implement network segmentation to restrict management interface access, while monitoring for suspicious authentication requests and unusual process execution from the auth_user_pass binary as interim detection measures until skills are developed to map this vulnerability class to MITRE techniques like T1190 (Exploit Public-Facing Application) and T1548 (Abuse Elevation Control Mechanism).
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-90823. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation