Vulnerability record · CVE-2024-12856 · published 27 December 2024
CVE-2024-12856: Four-Faith F3x24/F3x36 routers OS command injection via apply.cgi
Four Faith · F3x36 Firmware
Four-Faith router models F3x24 and F3x36 contain an OS command injection flaw in apply.cgi, reachable when modifying the system time over HTTP. Firmware version 2.0 is confirmed affected, and because that firmware ships default credentials, unchanged credentials turn the issue into unauthenticated remote command execution.
Description
The Four-Faith router models F3x24 and F3x36 are affected by an operating system (OS) command injection vulnerability. At least firmware version 2.0 allows authenticated and remote attackers to execute arbitrary OS commands over HTTP when modifying the system time via apply.cgi. Additionally, this firmware version has default credentials which, if not changed, would effectively change this vulnerability into an unauthenticated and remote OS command execution issue.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityHigh CVSS (7.2) command injection with public exploit references and very high EPSS, though exploitation requires authentication unless default credentials remain unchanged.
What it is
Four-Faith router models F3x24 and F3x36 contain an OS command injection flaw in apply.cgi, reachable when modifying the system time over HTTP. Firmware version 2.0 is confirmed affected, and because that firmware ships default credentials, unchanged credentials turn the issue into unauthenticated remote command execution.
Impact
An attacker can execute arbitrary OS commands on the device, gaining full control of the router with high confidentiality, integrity and availability impact. With default credentials left in place, this is reachable without any authentication.
Attack surface
Reached over the network via HTTP requests to apply.cgi during system time modification; the CVSS vector requires high privileges (PR:H), but the description notes default credentials would make it effectively unauthenticated. No user interaction is required (UI:N).
Exploitation
Not listed in CISA KEV, but EPSS is very high at 0.8422 (99.7th percentile) and multiple references are tagged Exploit, indicating public exploit material exists. No ransomware group usage is documented.
What to do
- Apply the vendor firmware fix for F3x24 and F3x36 as soon as it is available; treat firmware 2.0 as vulnerable.
- Immediately change default credentials on all affected routers and enforce strong unique admin passwords.
- Restrict HTTP management access to trusted internal networks or a management VLAN; never expose apply.cgi to the internet.
- Disable remote WAN administration and block inbound access to the router web interface at the perimeter.
- If patching is not possible, isolate affected devices on a segmented network and monitor them closely.
Detection
- Monitor HTTP requests to apply.cgi, especially those containing system time parameters with shell metacharacters.
- Alert on unexpected outbound connections or new processes spawned from the router's web server process.
- Audit router logs for authentication using default credentials and for management logins from untrusted source IPs.
- Baseline and alert on configuration changes to system time or admin credentials outside maintenance windows.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://ducklingstudio.blog.fc2.com/blog-entry-392.html | ExploitThird Party Advisory |
| https://vulncheck.com/advisories/four-faith-time | Third Party Advisory |
| https://vulncheck.com/blog/four-faith-cve-2024-12856 | ExploitThird Party Advisory |
| https://vulncheck.com/blog/four-faith-cve-2024-12856 | ExploitThird Party Advisory |
Track CVE-2024-12856 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-12856), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.