Hackers exploit Four-Faith router flaw to open reverse shells

Teilen:

Threat actors are exploiting a post-authentication remote command injection vulnerability in Four-Faith routers tracked as CVE-2024-12856 to open reverse shells back to the attackers.

The malicious activity was discovered by VulnCheck, who informed Four-Faith about the active exploitation on December 20, 2024. However, it is unclear if security updates for the vulnerability are currently available.

“We notified Four-Faith and our customers about this issue on December 20, 2024. Questions about patches, affected models, and affected firmware versions should be directed at Four-Faith.” explains the VulnCheck report.

Flaw details and scope

CVE-2024-12856 is an OS command injection flaw impacting Four-Faith router models F3x24 and F3x36, typically deployed in energy and utilities, transportation, telecommunications, and manufacturing sectors.

VulnCheck says hackers can gain access to those devices because many are configured with default credentials, which are easy to brute force.

The attack begins with the transmission of a specially crafted HTTP POST request to the router’s ‘/apply.cgi’ endpoint targeting the ‘adj_time_year’ parameter.

This is a parameter used for adjusting the system time, but it can be manipulated to include a shell command.

VulnCheck warns that the current attacks are similar to those targeting CVE-2019-12168, a similar flaw through the apply.cgi endpoint, but which performs code injection through the “ping_ip” parameter.

VulnCheck shared a sample payload that creates a reverse shell to an attacker’s computer, giving them full remote access to the routers.

Setting up a reverse shell
Setting up a reverse shell
Source: VulnCheck

After the device’s compromise, the attackers may modify its configuration files for persistence, explore the network for other devices to pivot to, and generally escalate the attack.

Censys reports that there are currently 15,000 internet-facing Four-Faith routers that could become targets.

Users of those devices should ensure they’re running the latest firmware version for their model and change the default credentials to something unique and strong (long).

VulnCheck has also shared a Suricata rule to detect CVE-2024-12856 exploitation attempts and block them in time.

Finally, users should contact their Four-Faith sales representative or customer support agent to request advice on how to mitigate CVE-2024-12856.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
5:23 am, Apr. 21, 2025
Wetter-Symbol 10°C
L: 9° | H: 10°
light rain
Luftfeuchtigkeit: 87 %
Druck: 1007 mb
Wind: 3 mph ENE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0.47 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:51 am
Sonnenuntergang: 8:06 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
9° | 10°°C 1 mm 100% 9 mph 87 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
8° | 16°°C 0 mm 0% 10 mph 89 % 1017 mb 0 mm/h
Mi. Apr. 23 10:00 pm
Wetter-Symbol
8° | 14°°C 1 mm 100% 14 mph 92 % 1018 mb 0 mm/h
Do. Apr. 24 10:00 pm
Wetter-Symbol
8° | 16°°C 0.2 mm 20% 9 mph 83 % 1024 mb 0 mm/h
Fr. Apr. 25 10:00 pm
Wetter-Symbol
8° | 16°°C 0 mm 0% 9 mph 89 % 1025 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
10° | 10°°C 0 mm 0% 3 mph 87 % 1007 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
11° | 12°°C 0 mm 0% 3 mph 77 % 1008 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
15° | 15°°C 0 mm 0% 7 mph 50 % 1009 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
15° | 15°°C 1 mm 100% 9 mph 69 % 1009 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
14° | 14°°C 1 mm 100% 7 mph 84 % 1011 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
11° | 11°°C 0 mm 0% 6 mph 87 % 1013 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
9° | 9°°C 0 mm 0% 7 mph 89 % 1014 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
8° | 8°°C 0 mm 0% 5 mph 88 % 1015 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€76,312.09
2.49%
Ethereum(ETH)
€1,432.44
1.60%
Fesseln(USDT)
€0.87
0.00%
XRP(XRP)
€1.85
1.70%
Solana(SOL)
€122.11
-0.87%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.140156
1.22%
Shiba Inu(SHIB)
€0.000011
2.51%
Pepe(PEPE)
€0.000007
3.53%
Nach oben scrollen