CVE-2024-9643
04.02.2025, 15:15
The Four-FaithF3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative web server. An attacker with knowledge of the credentials can gain administrative access via crafted HTTP requests. This issue appears similar to CVE-2023-32645.Enginsight
Vendor | Product | Version |
---|---|---|
four-faith | f3x36_firmware | 2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-489 - Active Debug CodeThe application is deployed to unauthorized actors with debugging code still enabled or active, which can create unintended entry points or expose sensitive information.
- CWE-798 - Use of Hard-coded CredentialsThe software contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.