Industrial Routers Become Reusable Botnet Infrastructure

Four-Faith F3x36 routers are no longer just edge connectivity gear. A compromise here can give attackers durable admin control over remote sites, and the standard perimeter-patch mindset misses that the whole distributed location can be folded into botnet operations or used as a foothold into local networks. CrowdSec says exploitation tied to CVE-2024-9643 has surged into mass exploitation. The flaw is a critical authentication bypass with a CVSS score of 9.8, driven by hard-coded credentials in the web interface, and observed activity now spans utilities, warehouses, retail sites, branch infrastructure, and other distributed environments. The risk is not limited to one appliance. In this deployment model, a single compromised router can become reusable attacker infrastructure across critical sectors, and that control can persist at remote sites long after the initial exploit attempt.

Part of the PlainSec briefing for 2026-05-21

Sources