Skip to content
Critical Exploitation of Four-Faith Routers in Botnet Campaign

Critical Exploitation of Four-Faith Routers in Botnet Campaign

First seen 19 May 2026, 15:51 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 20, 2026 at 15:26 UTC
  • Four-Faith industrial routers are targeted due to CVE-2024-9643, a critical flaw.
  • Exploitation attempts have surged, indicating a transition to large-scale botnet operations.
  • Organizations using affected routers must take immediate action to mitigate risks.

Four-Faith industrial cellular routers are under active attack due to a critical authentication bypass vulnerability, CVE-2024-9643, published on February 4, 2025. Security researchers report a significant increase in exploitation attempts, indicating a shift from probing to large-scale hijacking of these devices for botnet creation. The vulnerability primarily affects Four-Faith F3x36 industrial routers, which are being rapidly weaponized by attackers. This campaign poses a serious risk to industrial infrastructure, as compromised routers can be repurposed for malicious activities. The ongoing exploitation highlights the urgent need for organizations using these devices to implement security measures and monitor for suspicious activity.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 124d ago How this analysis works

Timeline

2025-02-04
CVE-2024-9643 published
A critical authentication bypass vulnerability affecting Four-Faith F3x36 routers was disclosed.
Gbhackers
Recent
Surge in exploitation attempts
Security researchers reported a sharp rise in attempts to exploit CVE-2024-9643, indicating a growing threat.
Cybersecuritynews

More articles in this cluster (6)

Following this threat?

Track CVE-2024-9643 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed