CVE-2024-9643
The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative web server. An attacker with knowledge of the credentials can gain administrative access via crafted HTTP requests. This issue appears similar to CVE-2023-32645.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 3.04%
- CWE
- CWE-489, CWE-798
- Published
- 2025-02-04
- Last modified
- 2026-03-13
Affected products
- Four-Faith F3x36
Weakness type
Related vulnerabilities
- CVE-2026-6485 — UEFI BIOS embedded Shell can be used to bypass Secure Boot
- CVE-2026-77545 — A malicious actor with access to the network, low privileges and under certain conditions could...
- CVE-2026-66787 — Lighthouse: go pprof profiling endpoint enabled unconditionally on lighthouse-agent :8082
- CVE-2026-66405 — DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be...
- CVE-2026-66403 — DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor...
- CVE-2026-41186 — Unauthenticated Go pprof exposure in Calico debug server
- CVE-2026-65893 — Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera
- CVE-2026-58378 — Allwinner TV Box TV98 ADB exposed on network