Four-Faith F3x36 Router Authentication Bypass Vulnerability via Hard-Coded Credentials

Vulnerability

An authentication bypass vulnerability has been identified in the Four-Faith F3x36 router running firmware v2.0.0. This vulnerability arises from hard-coded credentials in the administrative web server, allowing an attacker who knows the credentials to gain administrative access by sending crafted HTTP requests.

Impact

Exploitation of this vulnerability allows for unauthorized administrative access to the router's web interface.

Reproduction

The vulnerability can be reproduced by sending an HTTP request to the router's Status_Router.asp endpoint without any authorization headers. The response will indicate a 401 Unauthorized status. Then, send another request to the same endpoint, this time including the hard-coded debug credentials in the Authorization header. The response will confirm successful authentication by returning the requested page.

Remediation

Users are advised to update to the latest firmware version, which addresses this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.1
remediation
0.0
relevance
0.0
threat
6.5
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.