Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Mindgard Raises $30M to Secure AI Systems Against Emerging Threats
August 12, 2026
City-Forum Hackers Exploit Salesforce, ServiceNow Critical Vulnerabilities
August 12, 2026
Palo Alto Networks Patches 11 Vulnerabilities in PAN-OS, GlobalProtect, Prisma Access
August 12, 2026
Home/CyberSecurity News/Critical Vulnerabilities in Four-Faith Routers Let Attackers Hijack Devices
CyberSecurity News

Critical Vulnerabilities in Four-Faith Routers Let Attackers Hijack Devices

Key Takeaways A critical authentication bypass vulnerability (CVE-2024-9643) in Four-Faith F3x36 industrial cellular routers is being actively exploited. The flaw, rated 9.8 CVSS, allows attackers to...

Sarah simpson
Sarah simpson
May 19, 2026 3 Min Read
67 0

Key Takeaways

  • A critical authentication bypass vulnerability (CVE-2024-9643) in Four-Faith F3x36 industrial cellular routers is being actively exploited.
  • The flaw, rated 9.8 CVSS, allows attackers to gain full administrative control over affected devices due to hard-coded credentials.
  • Threat actors are leveraging this vulnerability to compromise routers and integrate them into botnets for DDoS attacks, malicious traffic proxying, and lateral movement.
  • Organizations utilizing these routers are advised to apply vendor updates, restrict management interface access, and enhance network monitoring.

Critical Flaw in Four-Faith Routers Fuels Botnet Expansion

A severe vulnerability, designated as CVE-2024-9643, within Four-Faith industrial routers is now under widespread active exploitation, enabling threat actors to commandeer devices and integrate them into growing botnet infrastructures.

Table Of Content

  • Key Takeaways
  • Critical Flaw in Four-Faith Routers Fuels Botnet Expansion
  • CVE-2024-9643: A Gateway to Router Hijacking
  • Four-Faith Routers Become Botnet Targets
  • What You Should Do

Cybersecurity researchers at CrowdSec have documented a significant escalation in exploitation attempts against these devices, indicating a shift from initial reconnaissance to sustained, large-scale abuse campaigns.

CVE-2024-9643: A Gateway to Router Hijacking

The core of the issue lies in CVE-2024-9643, an authentication bypass flaw impacting Four-Faith F3x36 industrial cellular routers. This critical vulnerability is rooted in hard-coded administrative credentials embedded directly within the device’s web management interface. This design oversight permits attackers to craft specific HTTP requests, targeting endpoints like /Status_Router.asp, to achieve complete administrative access without undergoing proper authentication protocols.

With a CVSS score of 9.8, the vulnerability presents a significant risk, allowing unauthorized individuals to:

  • Circumvent login mechanisms and acquire administrator privileges.
  • Alter router configurations and manipulate network settings.
  • Extract sensitive operational data from the device.
  • Establish persistent control over the compromised router.

The availability of public exploit templates, including a Nuclei detection script, has further streamlined the process for automated scanning and exploitation, lowering the barrier to entry for malicious actors.

Exploit timeline (Source: Crowdsec)
Exploit timeline (Source: Crowdsec)

Four-Faith Routers Become Botnet Targets

While the vulnerability was initially disclosed on February 4, 2025, active exploitation in the wild commenced on April 20, 2026. According to CrowdSec’s telemetry data, by May 18, at least 139 distinct IP addresses had been implicated in these attacks. The rapid surge in malicious activity led to the issue being reclassified into the “Mass Exploitation” phase on May 12, 2026.

The primary objective observed in 76% of these attacks is the complete takeover of the router infrastructure. Once compromised, these routers are integrated into botnets, enabling threat actors to:

  • Initiate distributed denial-of-service (DDoS) attacks.
  • Proxy malicious traffic to obscure their true origin.
  • Utilize the compromised devices as strategic footholds for deeper lateral movement within networks.

The attack campaign demonstrates a global reach, with identified attack sources spanning the United Kingdom, Germany, the United States, and the Netherlands, indicative of sophisticated, automated scanning operations conducted at scale.

Attack location (Source: Crowdsec)
Attack location (Source: Crowdsec)

Four-Faith F3x36 routers are commonly deployed in critical industrial and remote operational environments, including commercial warehouses, retail establishments, utility infrastructure, and branch offices. These devices frequently operate at the network perimeter and often receive infrequent updates or monitoring, rendering them highly attractive targets for attackers. A compromised router not only provides persistent access but also allows for traffic interception and deeper infiltration into internal networks. Due to lax visibility and patching practices, these devices often become long-term assets within botnet infrastructure.

What You Should Do

Organizations employing Four-Faith routers must take immediate and decisive action to mitigate this threat:

  • Promptly apply any firmware updates provided by the vendor or supplier.
  • Implement strict access controls, such as firewalls or VPNs, to limit access to router management interfaces.
  • Actively monitor network traffic for any unusual outbound connections or suspicious scanning activities.
  • Deploy threat detection tools, such as CrowdSec, to identify and alert on exploitation attempts.
  • Utilize threat intelligence feeds, including CrowdSec CTI blocklists, to block known malicious IP addresses.

Security researchers, including teams from Cisco Talos and VulnCheck, have previously highlighted the inherent risks associated with hard-coded credentials in network devices, emphasizing the critical importance of secure configuration practices. As attackers continue to weaponize exposed edge devices, unpatched industrial routers remain a high-risk entry point for botnet expansion and broader cyberattacks.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitHackerPatchSecurityThreatVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

GitHub Action Vulnerability Exposes Workflow Credentials

Next Post

Critical Apache Flink RCE Vulnerability CVE-2023-49272 Patched

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Google Chrome 115 Patches Five High-Severity Use-After-Free Flaws
August 12, 2026
Eclipse Ransomware Launches RaaS, Targets Windows, Linux, ESXi
August 12, 2026
WhatsApp launches new scam alert feature to combat social engineering
August 12, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us