Critical Vulnerabilities in Four-Faith Routers Let Attackers Hijack Devices
Key Takeaways A critical authentication bypass vulnerability (CVE-2024-9643) in Four-Faith F3x36 industrial cellular routers is being actively exploited. The flaw, rated 9.8 CVSS, allows attackers to...
Key Takeaways
- A critical authentication bypass vulnerability (CVE-2024-9643) in Four-Faith F3x36 industrial cellular routers is being actively exploited.
- The flaw, rated 9.8 CVSS, allows attackers to gain full administrative control over affected devices due to hard-coded credentials.
- Threat actors are leveraging this vulnerability to compromise routers and integrate them into botnets for DDoS attacks, malicious traffic proxying, and lateral movement.
- Organizations utilizing these routers are advised to apply vendor updates, restrict management interface access, and enhance network monitoring.
Critical Flaw in Four-Faith Routers Fuels Botnet Expansion
A severe vulnerability, designated as CVE-2024-9643, within Four-Faith industrial routers is now under widespread active exploitation, enabling threat actors to commandeer devices and integrate them into growing botnet infrastructures.
Table Of Content
Cybersecurity researchers at CrowdSec have documented a significant escalation in exploitation attempts against these devices, indicating a shift from initial reconnaissance to sustained, large-scale abuse campaigns.
CVE-2024-9643: A Gateway to Router Hijacking
The core of the issue lies in CVE-2024-9643, an authentication bypass flaw impacting Four-Faith F3x36 industrial cellular routers. This critical vulnerability is rooted in hard-coded administrative credentials embedded directly within the device’s web management interface. This design oversight permits attackers to craft specific HTTP requests, targeting endpoints like /Status_Router.asp, to achieve complete administrative access without undergoing proper authentication protocols.
With a CVSS score of 9.8, the vulnerability presents a significant risk, allowing unauthorized individuals to:
- Circumvent login mechanisms and acquire administrator privileges.
- Alter router configurations and manipulate network settings.
- Extract sensitive operational data from the device.
- Establish persistent control over the compromised router.
The availability of public exploit templates, including a Nuclei detection script, has further streamlined the process for automated scanning and exploitation, lowering the barrier to entry for malicious actors.

Four-Faith Routers Become Botnet Targets
While the vulnerability was initially disclosed on February 4, 2025, active exploitation in the wild commenced on April 20, 2026. According to CrowdSec’s telemetry data, by May 18, at least 139 distinct IP addresses had been implicated in these attacks. The rapid surge in malicious activity led to the issue being reclassified into the “Mass Exploitation” phase on May 12, 2026.
The primary objective observed in 76% of these attacks is the complete takeover of the router infrastructure. Once compromised, these routers are integrated into botnets, enabling threat actors to:
- Initiate distributed denial-of-service (DDoS) attacks.
- Proxy malicious traffic to obscure their true origin.
- Utilize the compromised devices as strategic footholds for deeper lateral movement within networks.
The attack campaign demonstrates a global reach, with identified attack sources spanning the United Kingdom, Germany, the United States, and the Netherlands, indicative of sophisticated, automated scanning operations conducted at scale.

Four-Faith F3x36 routers are commonly deployed in critical industrial and remote operational environments, including commercial warehouses, retail establishments, utility infrastructure, and branch offices. These devices frequently operate at the network perimeter and often receive infrequent updates or monitoring, rendering them highly attractive targets for attackers. A compromised router not only provides persistent access but also allows for traffic interception and deeper infiltration into internal networks. Due to lax visibility and patching practices, these devices often become long-term assets within botnet infrastructure.
What You Should Do
Organizations employing Four-Faith routers must take immediate and decisive action to mitigate this threat:
- Promptly apply any firmware updates provided by the vendor or supplier.
- Implement strict access controls, such as firewalls or VPNs, to limit access to router management interfaces.
- Actively monitor network traffic for any unusual outbound connections or suspicious scanning activities.
- Deploy threat detection tools, such as CrowdSec, to identify and alert on exploitation attempts.
- Utilize threat intelligence feeds, including CrowdSec CTI blocklists, to block known malicious IP addresses.
Security researchers, including teams from Cisco Talos and VulnCheck, have previously highlighted the inherent risks associated with hard-coded credentials in network devices, emphasizing the critical importance of secure configuration practices. As attackers continue to weaponize exposed edge devices, unpatched industrial routers remain a high-risk entry point for botnet expansion and broader cyberattacks.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.