logo

Critical Flaw Exposes Four-Faith Routers to Remote Exploitation

ID: 1eebfca3-479c-5bdd-bf13-16f55d0f5ee4

STIX ID: report--1eebfca3-479c-5bdd-bf13-16f55d0f5ee4

Feed Name: HackRead

Threat Score
75/100

Date Published: 2024-12-30

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

**Executive summary:** VulnCheck disclosed CVE-2024-12856, a critical post-authentication RCE affecting Four-Faith F3x24/F3x36 routers via the /apply.cgi adj_time_year parameter; active exploitation has been observed, roughly 15,000 internet-facing devices use default credentials, and VulnCheck provided detection (Suricata rule) and remediation advice including firmware updates and credential changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.