Vulnerability Intelligence Report
Four-Faith F3x36 bapply.cgi Auth Bypass
CVE-2024-9644
The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to an authentication bypass vulnerability in the administrative web server. Authentication is not enforced on some administrative functionality when using the "bapply.cgi" endpoint instead of the normal "apply.cgi" endpoint. A remote and unauthenticated can use this vulnerability to modify settings or chain with existing authenticated vulnerabilities.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:0.64%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-489 ↗CWE-489 Active Debug Code
CWE-306 ↗CWE-306 Missing Authentication for Critical Function
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Four-Faith | F3x36 | 2.0.0 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.640%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | VulnCheck · Bug Bounty Provider · USA |
| Reserved | 2024-10-08T18:08:01 |
| Published | 2025-02-04T14:58:03 |
| Last Updated | 2025-11-19T20:35:28 |
Community Chatter & Buzz