logo

Mass Exploitation Alert: Hardcoded Credentials in Four-Faith Industrial Routers (CVE-2024-9643) Hijacked for Botnets

ID: 5d606522-74a5-5b60-878f-baf4da8f7632

STIX ID: report--5d606522-74a5-5b60-878f-baf4da8f7632

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Ddos

...
...

CrowdSec reports that CVE-2024-9643, a critical (CVSS 9.8) authentication-bypass in Four-Faith F3x36 industrial cellular routers — caused by hard-coded administrative credentials — has moved into mass exploitation; attackers using public detection scripts (including a Nuclei template) and broadly distributed scanning are seizing devices to build botnets, pivot into internal networks, and proxy malicious traffic, and organizations are urged to patch firmware, restrict management access from the public internet, and audit outbound edge-device traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.