Mehr als 15.000 Four-Faith-Router durch neue Sicherheitslücke aufgrund von Standard-Zugangsdaten gefährdet

Teilen:

A high-severity flaw impacting select Four-Faith industrial routers has come under active exploitation in the wild, according to new findings from VulnCheck.

The vulnerability, tracked as CVE-2024-12856 (CVSS score: 7.2), has been described as an operating system (OS) command injection bug affecting router models F3x24 and F3x36.

The severity of the shortcoming is lower due to the fact that it only works if the remote attacker is able to successfully authenticate themselves. However, if the default credentials associated with the routers have not been changed, it could result in unauthenticated OS command execution.

In the attack detailed by VulnCheck, the unknown threat actors have been found to leverage the router’s default credentials to trigger exploitation of CVE-2024-12856 and launch a reverse shell for persistent remote access.

The exploitation attempt originated from the IP address 178.215.238[.]91, which has been previously used in connection with attacks seeking to weaponize CVE-2019-12168, another remote code execution flaw affecting Four-Faith routers. According to threat intelligence firm GreyNoise, efforts to exploit CVE-2019-12168 have been recorded as recently as December 19, 2024.

“The attack can be conducted against, at least, the Four-Faith F3x24 and F3x36 over HTTP using the /apply.cgi endpoint,” Jacob Baines said in a report. “The systems are vulnerable to OS command injection in the adj_time_year parameter when modifying the device’s system time via submit_type=adjust_sys_time.”

Data from Censys shows that there are over 15,000 internet-facing devices. There is some evidence suggesting that attacks exploiting the flaw may have been ongoing since at least early November 2024.

Baines told The Hacker News that “the attacks are and aren’t widespread,” adding “there is a small amount of attackers, but they appear to be spamming the entire internet (at a very low rate).” The attacks culminated in the download of a Mirai-like payload.

There is currently no information about the availability of patches, although VulnCheck stated that it responsibly reported the flaw to the Chinese company on December 20, 2024. The Hacker News has reached out to Four-Faith for comment prior to the publication of this story and will update the piece if we hear back.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
3:16 am, Juni 11, 2025
Wetter-Symbol 14°C
L: 12° | H: 15°
broken clouds
Luftfeuchtigkeit: 80 %
Druck: 1020 mb
Wind: 9 mph ENE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 81%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:16 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
12° | 15°°C 0 mm 0% 12 mph 83 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
14° | 25°°C 0.35 mm 35% 12 mph 77 % 1016 mb 0 mm/h
Fr. Juni 13 10:00 pm
Wetter-Symbol
16° | 27°°C 0.5 mm 50% 11 mph 86 % 1020 mb 0 mm/h
Sa. Juni 14 10:00 pm
Wetter-Symbol
17° | 23°°C 0.21 mm 21% 14 mph 90 % 1020 mb 0 mm/h
So. Juni 15 10:00 pm
Wetter-Symbol
13° | 22°°C 0.22 mm 22% 9 mph 85 % 1025 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
13° | 14°°C 0 mm 0% 5 mph 80 % 1020 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
14° | 15°°C 0 mm 0% 6 mph 83 % 1020 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
18° | 20°°C 0 mm 0% 7 mph 79 % 1021 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
22° | 22°°C 0 mm 0% 8 mph 68 % 1020 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
25° | 25°°C 0 mm 0% 11 mph 49 % 1018 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
22° | 22°°C 0 mm 0% 12 mph 56 % 1017 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 10 mph 67 % 1017 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
15° | 15°°C 0 mm 0% 9 mph 70 % 1016 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€96,008.27
0.09%
Ethereum(ETH)
€2,441.01
3.40%
Fesseln(USDT)
€0.87
-0.02%
XRP(XRP)
€2.00
-1.00%
Solana(SOL)
€144.20
3.12%
USDC(USDC)
€0.87
-0.01%
Dogecoin(DOGE)
€0.171561
1.04%
Shiba Inu(SHIB)
€0.000011
0.84%
Pepe(PEPE)
€0.000011
1.93%
Peanut das Eichhörnchen(PNUT)
€0.255379
1.55%
Nach oben scrollen