CVE-2024-9643

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Feb 4, 2025
CWE ID 489
CWE ID 798

Summary

CVE-2024-9643: Four-Faith F3x36 routers running firmware version 2.0.0 are susceptible to authentication bypass due to hard-coded credentials in the administrative web server. This vulnerability grants attackers unauthorized administrative access through crafted HTTP requests, resembling the authentication bypass issue in CVE-2023-32645.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • F3X36

Affected Vendors

  • Xiamen Four-Faith Communication Technology Co.Ltd