Thousands of industrial routers vulnerable to command injection flaw
ID: ea3f8de3-dae6-52d2-a7dd-9ecf92114751
STIX ID: report--ea3f8de3-dae6-52d2-a7dd-9ecf92114751
Feed Name: CyberScoop
Threat Score
A post-authentication remote command-injection vulnerability (CVE-2024-12856) affecting Four-Faith F3x24 and F3x36 industrial routers — which ship with hardcoded default credentials — is being exploited in the wild to deploy a Mirai variant; researchers observed malicious IP activity, honeypot detections, a public exploit demonstration, and estimate at least ~15,000 potentially vulnerable devices, while VulnCheck and others have published detection guidance and Suricata rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
