CVE-2024-9643Active Exploitation(four-faith / f3x36)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch four-faith f3x36 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative web server. An attacker with knowledge of the credentials can gain administrative access via crafted HTTP requests. This issue appears similar to CVE-2023-32645.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-489CWE-798

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • f3x36
  • f3x36_firmware

Threat summary

  • Active exploitation appears in 5 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days

What's happening

  • Active exploitation reported across 5 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-05-19); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
f3x36f3x36_firmware

2 versions affected across 2 products

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-02-17: 1Mentions · 2026-05-18: 1Mentions · 2026-05-19: 3Mentions · 2026-05-20: 1PoC Mentioned / Linked · 2026-02-17: 1Active Exploitation · 2026-05-18: 1Active Exploitation · 2026-05-19: 3Active Exploitation · 2026-05-20: 1Patch / Workaround · 2026-05-19: 2Patch / Workaround · 2026-05-20: 1Technical Details · 2026-02-17: 1Technical Details · 2026-05-19: 3Technical Details · 2026-05-20: 102-1705-1805-1905-20
Signal classification2 categories
Active Exploitation
583.3%
Disclosure
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-171
Disclosure1
2026-05-181
Active Exploitation1
2026-05-193
Active Exploitation3
2026-05-201
Active Exploitation1
Full discourse6 posts
  • Gray Hats@the_yellow_fall
    Active Exploitation

    CrowdSec warns CVE-2024-9643 in Four-Faith routers has hit mass exploitation phase. Attackers abuse hardcoded logins to build botnets. Patch now! #FourFaith #IoT #BotnetAlert #CyberSecurity #InfoSec #VulnerabilityAlert #CVE #MassExploitation https://securityonline.info/four-faith-industrial-routers-mass-exploitation-cve-2024-9643/ https://t.co/ZcVN0Hvf1O

    Post summary

    CVE-2024-9643 is currently being widely exploited in Four‑Faith routers via hardcoded credentials, and a patch is urgently needed.

    01000269
    12.2K followersView on X
  • CrowdSec@Crowd_Security
    Active Exploitation

    🚨 In this week’s newsletter, we cover CVE-2024-9643, a Four-Faith router authentication bypass now moving into mass exploitation. We break down how attackers are turning exposed industrial routers into botnet infrastructure and what defenders should do next. Read the full analysis and protect your systems 👉 https://www.crowdsec.net/vulntracking-report/cve-2024-9643-four-faith-router-authentication-bypass

    Post summary

    The text announces that CVE-2024‑9643, an authentication bypass on Four‑Faith routers, is currently being widely exploited to create botnets, urging defenders to read the full analysis.

    00010332
    19.5K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2024-9643 - critical 🚨 Four-Faith F3x36 - Authentication Bypass > Four-Faith F3x36 router with firmware v2.0.0 contains an authentication bypass caused... 👾 https://cloud.projectdiscovery.io/library/CVE-2024-9643 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces a critical authentication bypass vulnerability (CVE‑2024‑9643) in the Four‑Faith F3x36 router firmware v2.0.0 and links to a resource that likely contains additional details or a PoC.

    00010178
    888 followersView on X
  • Vistem Solutions@VistemSolutions
    Active Exploitation

    Exposed edge devices remain a top target for attackers. The mass exploitation of CVE-2024-9643 in Four-Faith F3x36 routers is a reminder that authentication bypass flaws can quickly turn vulnerable routers into botnet nodes, proxy infrastructure, or entry points into business networks. What organizations should prioritize now: - Identify any Four-Faith F3x36 routers and confirm exposure status - Apply vendor patches or mitigations immediately where available - Remove direct internet exposure and restrict management access with VPN/Zero Trust and IP allowlisting - Change default credentials and rotate administrative passwords and keys - Monitor for unusual outbound traffic, configuration changes, new users, and signs of botnet activity - Segment edge devices from critical systems to reduce lateral movement risk 𝗩𝗶𝘀𝘁𝗲𝗺 𝗘𝗹𝗲𝘃𝗮𝘁𝗲 𝗽𝗼𝘄𝗲𝗿𝗲𝗱 𝗯𝘆 𝗩𝗶𝘀𝘁𝗲𝗺𝗦𝗲𝗰𝘂𝗿𝗲𝗣𝗿𝗼 helps organizations validate exposure, strengthen network security, and reduce infrastructure risk with vCISO-led strategy, continuous monitoring, and measurable outcomes. Contact: sales@vistem.com | http://www.vistem.com?utm_source=in_page&utm_medium=Vistem+Solutions%2C+Inc.&utm_campaign=publer #Cybersecurity #RouterSecurity #FourFaith #CVE #VulnerabilityManagement #Botnet #NetworkSecurity #IncidentResponse #ZeroTrust #CyberResilience #VistemElevate #VistemSecurePro #VistemSolutions #SecurityCompliance https://www.crowdsec.net/vulntracking-report/cve-2024-9643-four-faith-router-authentication-bypass?utm_source=in_page&utm_medium=Vistem+Solutions%2C+Inc.&utm_campaign=publer

    Post summary

    CVE-2024-9643 has been widely exploited on Four‑Faith F3x36 routers, turning them into botnet nodes; urgent patching, network segmentation, and management hardening are urged.

    0000048
    79 followersView on X
  • moton@moton
    Active Exploitation

    Mass Exploitation Alert: Hardcoded Credentials in Four-Faith Industrial Routers (CVE-2024-9643) Hijacked for Botnets - https://securityonline.info/four-faith-industrial-routers-mass-exploitation-cve-2024-9643/

    Post summary

    CVE‑2024‑9643, a hardcoded‑credentials flaw in Four‑Faith industrial routers, is being widely exploited to hijack devices for botnets, with no patch or PoC referenced in the text.

    0000053
    659 followersView on X
  • CCB Alert@CCBalert
    Active Exploitation

    Warning: #CrowdSec Network observed massive exploitation of CVE-2024-9643, a Critical Authentication Bypass in #Four-Faith F3x36 router. https://www.crowdsec.net/vulntracking-report/cve-2024-9643-four-faith-router-authentication-bypass #Patch #Patch #Patch if you haven't already!

    Post summary

    CrowdSec reports widespread exploitation of CVE‑2024‑9643, an authentication bypass in Four‑Faith routers, and urges users to apply the latest patch immediately.

    00000200
    7.2K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWfour-faithf3x36---
OSfour-faithf3x36_firmware2.0--

Explore more