CVE-2024-9644 – Four-Faith F3x36 Router Authentication Bypass Vulnerability

The following table lists the changes that have been made to the
CVE-2024-9644 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Feb. 04, 2025

    Action Type Old Value New Value
    Added Description The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to an
    authentication bypass vulnerability in the administrative web server. Authentication is not enforced on some administrative functionality when using the “bapply.cgi” endpoint instead of the normal “apply.cgi” endpoint. A remote and unauthenticated can use this vulnerability to modify settings or chain with existing authenticated vulnerabilities.
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Added CWE CWE-306
    Added CWE CWE-489
    Added Reference https://vulncheck.com/advisories/four-faith-hidden-api
Share the Post:

Related Posts