First published: Tue Feb 04 2025(Updated: )
The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative web server. An attacker with knowledge of the credentials can gain administrative access via crafted HTTP requests. This issue appears similar to CVE-2023-32645.
Credit: disclosure@vulncheck.com
Affected Software | Affected Version | How to fix |
---|---|---|
Four-Faith F3x36 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-9643 is considered a high-severity vulnerability due to the potential for unauthorized administrative access.
To fix CVE-2024-9643, update the Four-Faith F3x36 router firmware to the latest version that removes hard-coded credentials.
CVE-2024-9643 affects the Four-Faith F3x36 router running firmware version 2.0.0.
CVE-2024-9643 allows attackers to bypass authentication and gain administrative access through crafted HTTP requests.
Yes, CVE-2024-9643 can be exploited by attackers who possess the hard-coded credentials to access the router's administrative interface.