ZeroHour

CVE-2024-12856

PoC ×2large

OS Command Injection in Four-Faith F3x24/F3x36 Routers

CVSS 3.1
7.2 high
EPSS
84%p100
Published
()
Modified
AI analysis

Four-Faith industrial router models F3x24 and F3x36 running firmware version 2.0 are vulnerable to OS command injection (CWE-78) through the apply.cgi interface when an attacker modifies the system time over HTTP. The flaw is technically authenticated (CVSS 3.1: 7.2, network-adjacent-remote with high privileges required), but the same firmware ships with default credentials, so any device where defaults were not changed is effectively exposed to unauthenticated remote OS command execution. A successful attacker can run arbitrary commands on the router, gaining full device compromise that can be used for further access or recruitment into botnets. Four-Faith deployments — typically industrial and remote-connectivity routers — are affected, with at least 15,000 routers exposed to the internet and many retaining default credentials. Exploitation is confirmed in the wild: a Mirai botnet variant has weaponized the flaw for DDoS attacks, and the RondoDox botnet is also targeting it, consistent with a high EPSS score (84.2% probability of exploitation within 30 days, 100th percentile).

What to do: Update F3x24/F3x36 devices to the latest firmware available from Four-Faith and verify apply.cgi handling is fixed; as an immediate mitigation, change default administrator credentials and restrict HTTP management access to trusted networks. Check devices for signs of botnet infection (unexpected outbound traffic or Crontab/persistence changes) and prioritize patching given confirmed in-the-wild exploitation by Mirai and RondoDox botnets.

Affected
Four-Faith F3x24 router firmwareat least firmware version 2.0 (exact affected version range not specified in the data)
Four-Faith F3x36 router firmwareat least firmware version 2.0 (exact affected version range not specified in the data)
Estimated exposure
large≈15,000+ internet-exposed routers (headline scan count; total deployments likely higher) — Based on news reporting citing internet scans that found at least 15,000 Four-Faith routers exposed, many still using default credentials, with total F3x24/F3x36 deployment counts unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Four-Faith router models F3x24 and F3x36 are affected by an operating system (OS) command injection vulnerability. At least firmware version 2.0 allows authenticated and remote attackers to execute arbitrary OS commands over HTTP when modifying the system time via apply.cgi. Additionally, this firmware version has default credentials which, if not changed, would effectively change this vulnerability into an unauthenticated and remote OS command execution issue.

Vendors
four-faith
Products
f3x36 firmware, f3x24 firmware
Weakness
CWE-78, CWE-1392
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news