Mass Exploitation Alert: Hardcoded Credentials in Four-Faith Industrial Routers (CVE-2024-9643) Hijacked for Botnets
ID: 5d606522-74a5-5b60-878f-baf4da8f7632
STIX ID: report--5d606522-74a5-5b60-878f-baf4da8f7632
Feed Name: securityonline.info
CrowdSec reports that CVE-2024-9643, a critical (CVSS 9.8) authentication-bypass in Four-Faith F3x36 industrial cellular routers — caused by hard-coded administrative credentials — has moved into mass exploitation; attackers using public detection scripts (including a Nuclei template) and broadly distributed scanning are seizing devices to build botnets, pivot into internal networks, and proxy malicious traffic, and organizations are urged to patch firmware, restrict management access from the public internet, and audit outbound edge-device traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
