logo

Hackers exploit Four-Faith router flaw to open reverse shells

ID: d3b332c0-be12-5482-b193-0258ee066d8d

STIX ID: report--d3b332c0-be12-5482-b193-0258ee066d8d

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-12-30

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

VulnCheck has reported active exploitation of CVE-2024-12856, a post-auth remote command injection in Four-Faith F3x24/F3x36 routers that attackers exploit by sending crafted POST requests to /apply.cgi (adj_time_year) to spawn reverse shells; roughly 15,000 internet-facing devices may be exposed, and mitigation includes updating firmware, changing default credentials, and deploying the provided Suricata detection rule.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.