Thursday, October 8, 2026

Four-Faith Industrial Routers Targeted in Botnet Hijacking Campaign

Four-Faith industrial cellular routers are being actively targeted in a growing botnet campaign exploiting a critical authentication bypass flaw tracked as CVE-2024-9643.

Security researchers warn that attackers are rapidly weaponizing the vulnerability to hijack exposed devices and repurpose them as part of large-scale malicious infrastructure.

Four-Faith Industrial Routers Targeted

CVE-2024-9643 affects Four-Faith F3x36 industrial routers and carries a critical CVSS score of 9.8. The flaw stems from hard-coded administrative credentials embedded within the device’s web interface.

Exploit timeline (Source: Crowdsec)
Exploit timeline (Source: Crowdsec)

Attackers can exploit this weakness by sending specially crafted HTTP requests to management endpoints such as “/Status_Router.asp,” bypassing authentication entirely.

Once access is obtained, attackers gain full administrative control. This allows them to modify configurations, extract sensitive data, and maintain persistent control over the device.

Exploitation Timeline

  • February 4, 2025: Vulnerability publicly disclosed
  • April 15, 2026: CrowdSec releases detection signatures
  • April 20, 2026: First exploitation attempts observed in the wild
  • May 12, 2026: Classified as “Mass Exploitation”
  • May 18, 2026: 139 unique attacking IPs identified

The rapid escalation highlights how quickly threat actors operationalize publicly known vulnerabilities, especially when exploitation requires minimal effort.

According to CrowdSec telemetry, attackers are primarily focused on infrastructure takeover. Around 76% of observed activity aligns with botnet-building objectives. Compromised routers are being used as proxy nodes, command relays, or entry points for further network intrusion.

Attack location (Source: Crowdsec)
Attack location (Source: Crowdsec)

Industries with distributed infrastructure, such as retail, logistics, and utilities, are particularly at risk. These routers are often deployed in remote or lightly monitored environments, making them attractive targets.

Attack traffic has been observed globally, with notable sources in:

  • United Kingdom
  • Germany
  • United States
  • Netherlands

This geographic spread suggests automated scanning and exploitation rather than targeted attacks.

The Four-Faith F3x36 router is widely used to connect remote sites and industrial systems. Because it sits at the network edge, a compromised device can:

  • Intercept or manipulate traffic
  • Expose internal systems
  • Serve as a persistent foothold for attackers

For example, an attacker controlling a router in a retail branch could quietly redirect traffic or use it to launch attacks against other organizations without detection.

Mitigation and Recommendations

Organizations using affected devices should take immediate action:

  • Apply firmware updates provided by Four-Faith or vendors without delay
  • Restrict access to router management interfaces, especially from the internet
  • Monitor network traffic for unusual activity or unauthorized configuration changes
  • Deploy intrusion detection solutions such as CrowdSec to identify exploitation attempts
  • Block known malicious IPs using threat intelligence feeds

Security researchers from Cisco Talos and VulnCheck have also published technical analyses and detection resources, including publicly available scanning templates, further lowering the barrier for attackers.

With active exploitation underway and automation increasing, unpatched routers risk becoming part of the next wave of botnet-driven cyberattacks.

Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR:...

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489,...

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to...

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to...

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational...

wolfSSH Patches 5 Security Vulnerabilities, Including Critical SSH Authentication Bypass

wolfSSL has released wolfSSH version 1.6.0, which addresses five...

Critical Gitea Vulnerabilities Allow Attackers to Bypass Authentication and Execute Code

Gitea has released version 28.0.0, addressing 20 vulnerabilities related...

Related Articles

Recent News