logo

Thousands of industrial routers vulnerable to command injection flaw 

ID: ea3f8de3-dae6-52d2-a7dd-9ecf92114751

STIX ID: report--ea3f8de3-dae6-52d2-a7dd-9ecf92114751

Feed Name: CyberScoop

Threat Score
75/100

Date Published: 2024-12-30

Date Updated: 2026-04-21

Author: djohnson

...
...

A post-authentication remote command-injection vulnerability (CVE-2024-12856) affecting Four-Faith F3x24 and F3x36 industrial routers — which ship with hardcoded default credentials — is being exploited in the wild to deploy a Mirai variant; researchers observed malicious IP activity, honeypot detections, a public exploit demonstration, and estimate at least ~15,000 potentially vulnerable devices, while VulnCheck and others have published detection guidance and Suricata rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.