ZeroHour
CyberScooppublished ()ingested @CyberScoopNews

Thousands of industrial routers vulnerable to command injection flaw

criticalExploit / PoC exploited in the wildimportance 60CVE-2024-12856

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-12856
OS Command Injection in Four-Faith F3x24/F3x36 Routers

Four-Faith industrial router models F3x24 and F3x36 running firmware version 2.0 are vulnerable to OS command injection (CWE-78) through the apply.cgi interface when an attacker modifies the system time over HTTP. The flaw is technically authenticated (CVSS 3.1: 7.2, network-adjacent-remote with high privileges required), but the same firmware ships with default credentials, so any device where defaults were not changed is effectively exposed to unauthenticated remote OS command execution. A successful attacker can run arbitrary commands on the router, gaining full device compromise that can be used for further access or recruitment into botnets. Four-Faith deployments — typically industrial and remote-connectivity routers — are affected, with at least 15,000 routers exposed to the internet and many retaining default credentials. Exploitation is confirmed in the wild: a Mirai botnet variant has weaponized the flaw for DDoS attacks, and the RondoDox botnet is also targeting it, consistent with a high EPSS score (84.2% probability of exploitation within 30 days, 100th percentile).

Do: Update F3x24/F3x36 devices to the latest firmware available from Four-Faith and verify apply.cgi handling is fixed; as an immediate mitigation, change default administrator credentials and restrict HTTP management access to trusted networks. Check devices for signs of botnet infection (unexpected outbound traffic or Crontab/persistence changes) and prioritize patching given confirmed in-the-wild exploitation by Mirai and RondoDox botnets.

7.284% PoC ×2
  • Four-Faith F3x24 router firmware at least firmware version 2.0 (exact affected version range not specified in the data)
  • Four-Faith F3x36 router firmware at least firmware version 2.0 (exact affected version range not specified in the data)
large≈15,000+ internet-exposed routers (headline scan count; total deployments likely higher)
Full article892 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The vulnerability, found in versions of Four-Faith routers, appears to have been exploited in the wild and has been connected to attempted infections of Mirai.

Listen to this article

0:00

Learn more.

On Dec. 27, VulnCheck detailed the vulnerability, tracked as CVE-2024-12856, wherein an attacker can leverage default credentials in Four-Faith F3x24 and F3x36 routers to remotely inject commands into the operating system. (Getty Images)

Thousands of industrial routers from a Chinese telecommunications equipment manufacturer are vulnerable to a post-authentication vulnerability, with indications it is already being exploited in the wild to infect devices with Mirai malware.

On Dec. 27, VulnCheck detailed the vulnerability, tracked as CVE-2024-12856, wherein an attacker can leverage default credentials in Four-Faith F3x24 and F3x36 routers to remotely inject commands into the operating system. 

Meanwhile, a malicious IP was observed attempting to leverage the vulnerability. VulnCheck Chief Technology Officer Jacob Baines wrote that his team identified the same user agent referenced in a November blog by DucklingStudio attempting to use the vulnerability to deploy a different malware payload.

Baines also posted a video demonstration of the flaw being exploited on X.

The vulnerability appears to be connected to the spread of a variant of Mirai, the infamous malware and botnet known to target Internet of Things devices. DucklingStudio used a honeypot to detect the malware on Nov. 9, and an update on Dec. 28 explicitly connected it to the listed CVE for Four-Faith’s industrial routers.

Variants of Mirai —first observed in 2016 and originally written by a group of teenagers to create botnets — remain one of the most popular forms of malware attacking IoT devices worldwide. According to Zscaler, Mirai was identified in over a third of all IoT malware attacks between June 2023 and May 2024, far outpacing other malware families, while more than 75% of blocked IoT transactions were linked to the malicious code.

VulnCheck wrote up a rule for detecting instances of infected routers using the open-source threat detection tool Suricata:

Detection rule for CVE-2024-12856 affecting Four-Faith industrial routers (Source: VulnCheck)

According to Censys, there are at least 15,000 connected routers potentially vulnerable to the flaw, and VulnCheck left open the possibility that additional router products may be affected. The National Institute of Standards and Technology’s National Vulnerability Database lists the severity of the bug at 7.2 and notes that firmware version 2.0 (and possibly others) allows for authenticated and remote command injection attacks over HTTP.

Cale Black, an initial access exploit engineer for VulnCheck, told CyberScoop that the affected equipment is primarily deployed as an industrial router, with a focus on IoT and 4G networking. Exposed routers were primarily located in Turkey, China, Spain and Hungary, while 16 other countries had at least one exposed and public Four-Faith system in place.

While the flaw does require the attacker to have existing authentication, the fact that the routers are hardcoded with default credentials that were identified as part of a previous CVE means “it can be used to trigger any command on the routers as the administrative user,” Black said.

He added that while VulnCheck has only confirmed exploitability in F3X24 and F3X36 routers, “it is common for functionality to be deployed across the product lines by Four-Faith” and that the company may have other routers that are similarly affected.

The listed CVE does not yet include details about patching or remediation. Baines noted in his blog that VulnCheck notified Four-Faith of the vulnerability and affected routers on Dec. 20, and directed further questions about remediation to the company.

Four-Faith did not return a request for comment sent through its website prior to publication. Black said that VulnCheck has communicated with Four-Faith about the vulnerability multiple times since initially reaching out on Dec. 20 and that his understanding is the company is currently testing the flaw on their end.

According to the company’s website, Four-Faith is headquartered in Xiamen, a city in the Southeastern province of Fujian, China. It specializes in manufacturing industrial routers, Internet of Things devices, modems and other wireless communications technologies, and claims to have exported its technologies to over 100 countries.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/iot-command-injection-industrial-routers-four-faith-mirai/