Summary: A critical OS command injection vulnerability in select Four-Faith routers is being actively exploited, allowing attackers to gain remote access. The flaw, CVE-2024-12856, poses a significant risk, especially if default credentials remain unchanged.
Threat Actor: Unknown | unknown
Victim: Four-Faith | Four-Faith
Key Point :
- Vulnerability CVE-2024-12856 has a CVSS score of 7.2 and affects router models F3x24 and F3x36.
- Exploitation requires authentication, but default credentials can lead to unauthenticated access.
- Attackers have been observed using default credentials to execute commands and establish persistent remote access.
- Exploitation attempts have been linked to an IP address previously associated with another vulnerability (CVE-2019-12168).
- Over 15,000 internet-facing devices are potentially at risk, with evidence of ongoing attacks since November 2024.
- No patches are currently available, and the vulnerability was reported to Four-Faith on December 20, 2024.
A high-severity flaw impacting select Four-Faith routers has come under active exploitation in the wild, according to new findings from VulnCheck.
The vulnerability, tracked as CVE-2024-12856 (CVSS score: 7.2), has been described as an operating system (OS) command injection bug affecting router models F3x24 and F3x36.
The severity of the shortcoming is lower due to the fact that it only works if the remote attacker is able to successfully authenticate themselves. However, if the default credentials associated with the routers have not been changed, it could result in unauthenticated OS command execution.
In the attack detailed by VulnCheck, the unknown threat actors have been found to leverage the router’s default credentials to trigger exploitation of CVE-2024-12856 and launch a reverse shell for persistent remote access.
The exploitation attempt originated from the IP address 178.215.238[.]91, which has been previously used in connection with attacks seeking to weaponize CVE-2019-12168, another remote code execution flaw affecting Four-Faith routers. According to threat intelligence firm GreyNoise, efforts to exploit CVE-2019-12168 have been recorded as recently as December 19, 2024.
“The attack can be conducted against, at least, the Four-Faith F3x24 and F3x36 over HTTP using the /apply.cgi endpoint,” Jacob Baines said in a report. “The systems are vulnerable to OS command injection in the adj_time_year parameter when modifying the device’s system time via submit_type=adjust_sys_time.”
Data from Censys shows that there are over 15,000 internet-facing devices. There is some evidence suggesting that attacks exploiting the flaw may have been ongoing since at least early November 2024.
There is currently no information about the availability of patches, although VulnCheck stated that it responsibly reported the flaw to the Chinese company on December 20, 2024. The Hacker News has reached out to Four-Faith for comment prior to the publication of this story and will update the piece if we hear back.
Source: https://thehackernews.com/2024/12/15000-four-faith-routers-exposed-to-new.html