# CVE-2024-9643

## Summary

- **CVE ID:** CVE-2024-9643
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-489, CWE-798
- **Published:** Feb 4, 2025
- **Last Modified:** Mar 13, 2026

## Description

The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative web server. An attacker with knowledge of the credentials can gain administrative access via crafted HTTP requests. This issue appears similar to CVE-2023-32645.

## Affected Products

- Four-Faith — F3x36 (2.0.0)

## References

- [CNA](https://vulncheck.com/advisories/four-faith-hard-coded-creds)
- [CNA](https://talosintelligence.com/vulnerability_reports/TALOS-2023-1752)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 3.04%
- **EPSS Percentile:** 86.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-09._