ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

15,000+ Four-Faith Routers Exposed to New Exploit Due to Default Credentials

highExploit / PoC exploited in the wildimportance 60CVE-2024-12856CVE-2019-12168

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-12168
Four-Faith Wireless Mobile Router F3x24 v1.0 devices allow remote code execution via the Command Shell (aka Administration > Commands) screen.

Four-Faith Wireless Mobile Router F3x24 v1.0 devices allow remote code execution via the Command Shell (aka Administration > Commands) screen.

NVD description · AI analysis pending
7.25%
  • four-faith f3x24 firmware
CVE-2024-12856
OS Command Injection in Four-Faith F3x24/F3x36 Routers

Four-Faith industrial router models F3x24 and F3x36 running firmware version 2.0 are vulnerable to OS command injection (CWE-78) through the apply.cgi interface when an attacker modifies the system time over HTTP. The flaw is technically authenticated (CVSS 3.1: 7.2, network-adjacent-remote with high privileges required), but the same firmware ships with default credentials, so any device where defaults were not changed is effectively exposed to unauthenticated remote OS command execution. A successful attacker can run arbitrary commands on the router, gaining full device compromise that can be used for further access or recruitment into botnets. Four-Faith deployments — typically industrial and remote-connectivity routers — are affected, with at least 15,000 routers exposed to the internet and many retaining default credentials. Exploitation is confirmed in the wild: a Mirai botnet variant has weaponized the flaw for DDoS attacks, and the RondoDox botnet is also targeting it, consistent with a high EPSS score (84.2% probability of exploitation within 30 days, 100th percentile).

Do: Update F3x24/F3x36 devices to the latest firmware available from Four-Faith and verify apply.cgi handling is fixed; as an immediate mitigation, change default administrator credentials and restrict HTTP management access to trusted networks. Check devices for signs of botnet infection (unexpected outbound traffic or Crontab/persistence changes) and prioritize patching given confirmed in-the-wild exploitation by Mirai and RondoDox botnets.

7.284% PoC ×2
  • Four-Faith F3x24 router firmware at least firmware version 2.0 (exact affected version range not specified in the data)
  • Four-Faith F3x36 router firmware at least firmware version 2.0 (exact affected version range not specified in the data)
large≈15,000+ internet-exposed routers (headline scan count; total deployments likely higher)
Full article381 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananDec 28, 2024Vulnerability / Threat Intelligence

A high-severity flaw impacting select Four-Faith industrial routers has come under active exploitation in the wild, according to new findings from VulnCheck.

The vulnerability, tracked as CVE-2024-12856 (CVSS score: 7.2), has been described as an operating system (OS) command injection bug affecting router models F3x24 and F3x36.

The severity of the shortcoming is lower due to the fact that it only works if the remote attacker is able to successfully authenticate themselves. However, if the default credentials associated with the routers have not been changed, it could result in unauthenticated OS command execution.

In the attack detailed by VulnCheck, the unknown threat actors have been found to leverage the router's default credentials to trigger exploitation of CVE-2024-12856 and launch a reverse shell for persistent remote access.

The exploitation attempt originated from the IP address 178.215.238[.]91, which has been previously used in connection with attacks seeking to weaponize CVE-2019-12168, another remote code execution flaw affecting Four-Faith routers. According to threat intelligence firm GreyNoise, efforts to exploit CVE-2019-12168 have been recorded as recently as December 19, 2024.

"The attack can be conducted against, at least, the Four-Faith F3x24 and F3x36 over HTTP using the /apply.cgi endpoint," Jacob Baines said in a report. "The systems are vulnerable to OS command injection in the adj_time_year parameter when modifying the device's system time via submit_type=adjust_sys_time."

Data from Censys shows that there are over 15,000 internet-facing devices. There is some evidence suggesting that attacks exploiting the flaw may have been ongoing since at least early November 2024.

Baines told The Hacker News that "the attacks are and aren't widespread," adding "there is a small amount of attackers, but they appear to be spamming the entire internet (at a very low rate)." The attacks culminated in the download of a Mirai-like payload.

There is currently no information about the availability of patches, although VulnCheck stated that it responsibly reported the flaw to the Chinese company on December 20, 2024. The Hacker News has reached out to Four-Faith for comment prior to the publication of this story and will update the piece if we hear back.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/12/15000-four-faith-routers-exposed-to-new.html