Four-Faith industrial cellular routers are being actively targeted in a growing botnet campaign exploiting a critical authentication bypass flaw tracked as CVE-2024-9643.
Security researchers warn that attackers are rapidly weaponizing the vulnerability to hijack exposed devices and repurpose them as part of large-scale malicious infrastructure.
CVE-2024-9643 affects Four-Faith F3x36 industrial routers and carries a critical CVSS score of 9.8. The flaw stems from hard-coded administrative credentials embedded within the device’s web interface.
Attackers can exploit this weakness by sending specially crafted HTTP requests to management endpoints such as “/Status_Router.asp,” bypassing authentication entirely.
Once access is obtained, attackers gain full administrative control. This allows them to modify configurations, extract sensitive data, and maintain persistent control over the device.
Exploitation Timeline
The rapid escalation highlights how quickly threat actors operationalize publicly known vulnerabilities, especially when exploitation requires minimal effort.
According to CrowdSec telemetry, attackers are primarily focused on infrastructure takeover. Around 76% of observed activity aligns with botnet-building objectives. Compromised routers are being used as proxy nodes, command relays, or entry points for further network intrusion.
Industries with distributed infrastructure, such as retail, logistics, and utilities, are particularly at risk. These routers are often deployed in remote or lightly monitored environments, making them attractive targets.
Attack traffic has been observed globally, with notable sources in:
This geographic spread suggests automated scanning and exploitation rather than targeted attacks.
The Four-Faith F3x36 router is widely used to connect remote sites and industrial systems. Because it sits at the network edge, a compromised device can:
For example, an attacker controlling a router in a retail branch could quietly redirect traffic or use it to launch attacks against other organizations without detection.
Organizations using affected devices should take immediate action:
Security researchers from Cisco Talos and VulnCheck have also published technical analyses and detection resources, including publicly available scanning templates, further lowering the barrier for attackers.
With active exploitation underway and automation increasing, unpatched routers risk becoming part of the next wave of botnet-driven cyberattacks.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…