CVE-2024-9644 – Four-Faith F3x36 Router Authentication Bypass Vulnerability

The following table lists the changes that have been made to the CVE-2024-9644 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received by [email protected]

    Feb. 04, 2025

    Action Type Old Value New Value
    Added Description The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to an authentication bypass vulnerability in the administrative web server. Authentication is not enforced on some administrative functionality when using the “bapply.cgi” endpoint instead of the normal “apply.cgi” endpoint. A remote and unauthenticated can use this vulnerability to modify settings or chain with existing authenticated vulnerabilities.
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Added CWE CWE-306
    Added CWE CWE-489
    Added Reference https://vulncheck.com/advisories/four-faith-hidden-api

نوشته های مشابه