CVE-2024-9643
CVSS 9.8 CRITICAL: the Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative web server. EPSS 3% (87º percentile).
Vulnerabilità ed exploit · Attacco IoT / OT
I router Four-Faith F3x36 non sono più soltanto dispositivi di connettività edge. Un compromesso qui può dare agli attaccanti un duraturo controllo admin sui siti remoti, e la mentalità standard di patch del perimetro trascura il fatto che l’intera sede distribuita può essere inglobata nelle operazioni della botnet o usata come punto d’appoggio verso le reti locali.
1 fonte · 20 mag
CVSS 9.8 CRITICAL: the Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative web server. EPSS 3% (87º percentile).
Industrial Cyber
CrowdSec flags rising exploitation of Four-Faith industrial routers as botnet activity grows across critical sectors - Industrial Cyber
CrowdSec researchers flag rising exploitation of Four-Faith industrial routers as botnet activity grows across critical sectors.
originalePart of the PlainSec briefing for 2026-05-21
Every edition of this story: I router industriali diventano infrastruttura botnet riutilizzabile