CVE-2024-9643
CVSS 9.8 CRITICAL: the Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative web server. EPSS 3% (87th percentile).
Vulnerabilities & Exploits · IoT / OT Attack
Four-Faith F3x36 routers are no longer just edge connectivity gear. A compromise here can give attackers durable admin control over remote sites, and the standard perimeter-patch mindset misses that the whole distributed location can be folded into botnet operations or used as a foothold into local networks.
CrowdSec says exploitation tied to CVE-2024-9643 has surged into mass exploitation. The flaw is a critical authentication bypass with a CVSS score of 9.8, driven by hard-coded credentials in the web interface, and observed activity now spans utilities, warehouses, retail sites, branch infrastructure, and other distributed environments.
The risk is not limited to one appliance. In this deployment model, a single compromised router can become reusable attacker infrastructure across critical sectors, and that control can persist at remote sites long after the initial exploit attempt.
1 source · May 20
CVSS 9.8 CRITICAL: the Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative web server. EPSS 3% (87th percentile).
Industrial Cyber
CrowdSec flags rising exploitation of Four-Faith industrial routers as botnet activity grows across critical sectors - Industrial Cyber
CrowdSec researchers flag rising exploitation of Four-Faith industrial routers as botnet activity grows across critical sectors.
originalPart of the PlainSec briefing for 2026-05-21
Every edition of this story: Industrial Routers Become Reusable Botnet Infrastructure