/Vulnerability Library

Four-Faith F3x36 - Authentication Bypass

CVE-2024-9643
Verified

Description

Four-Faith F3x36 router with firmware v2.0.0 contains an authentication bypass caused by hard-coded credentials in the administrative web server, letting attackers with knowledge of credentials gain administrative access via crafted HTTP requests.

Severity

Critical

CVSS Score

9.8

Exploit Probability

3%

Affected Product

f3x36

Published Date

February 16, 2026

Template Author

trader642

CVE-2024-9643.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2024-9643
CWE ID:
cwe-798

References

https://vulncheck.com/advisories/four-faith-hard-coded-credshttps://talosintelligence.com/vulnerability_reports/TALOS-2023-1752

Remediation Steps

Update to the latest firmware version provided by the vendor to fix hard-coded credential issues.