CVE-2024-12856Active Exploitation(four-faith / f3x24)

MEDIUMCVSS 7.2 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for four-faith f3x24 systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The Four-Faith router models F3x24 and F3x36 are affected by an operating system (OS) command injection vulnerability. At least firmware version 2.0 allows authenticated and remote attackers to execute arbitrary OS commands over HTTP when modifying the system time via apply.cgi. Additionally, this firmware version has default credentials which, if not changed, would effectively change this vulnerability into an unauthenticated and remote OS command execution issue.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-1392

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • f3x24
  • f3x24_firmware
  • f3x36
  • f3x36_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
f3x24f3x24_firmwaref3x36f3x36_firmware

2 versions affected across 4 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-04: 1Active Exploitation · 2026-08-04: 1Technical Details · 2026-08-04: 108-04
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows a coordinated botnet campaign targeting diagnostic tool interfaces through command injection vulnerabilities like CVE-2024-12856. Attackers gained root access and moved laterally within compromised networks. Runtime segmentation helps contain such post-compromise activity by limiting blast radius. #ThreatIntel 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/botnet-hunting-vulnerabilities-diagnostic-tools-2026

    Post summary

    This post reports that CVE-2024-12856 has been actively exploited by a botnet, granting attackers root access and lateral movement, highlighting the critical need for security mitigations.

    0000071
    1.9K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
HWfour-faithf3x24---
OSfour-faithf3x24_firmware2.0--
HWfour-faithf3x36---
OSfour-faithf3x36_firmware2.0--

Explore more