logo

Four-Faith Routers Exploited Through CVE-2024-12856 Vulnerability

ID: c90bd4b3-c71b-5e33-b9d7-214ee924bffe

STIX ID: report--c90bd4b3-c71b-5e33-b9d7-214ee924bffe

Feed Name: SOCRadar Blog

Threat Score
72/100

Date Published: 2024-12-31

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

SOCRadar reports that CVE-2024-12856 is a post-authentication OS command injection in Four-Faith F3x24/F3x36 routers (via /apply.cgi adj_time_year) being actively exploited to establish reverse shells and persistence; attacks target devices with default credentials and approximately 15,000 internet-exposed routers may be vulnerable. The report includes exploit details and an observed IP (178.215.238.91), provides a Suricata detection rule, and recommends firmware updates, replacing default credentials, restricting internet exposure, and regular audits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.