The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to an
authentication bypass vulnerability in the administrative web server. Authentication is not enforced on some administrative functionality when using the "bapply.cgi" endpoint instead of the normal "apply.cgi" endpoint. A remote and unauthenticated can use this vulnerability to modify settings or chain with existing authenticated vulnerabilities.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://vulncheck.com/advisories/four-faith-hidden-api |
![]() ![]() |
History
Fri, 19 Sep 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Four-faith
Four-faith f3x36 Four-faith f3x36 Firmware |
|
CPEs | cpe:2.3:h:four-faith:f3x36:-:*:*:*:*:*:*:* cpe:2.3:o:four-faith:f3x36_firmware:2.0:*:*:*:*:*:*:* |
|
Vendors & Products |
Four-faith
Four-faith f3x36 Four-faith f3x36 Firmware |
Tue, 15 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Tue, 04 Feb 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 04 Feb 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to an authentication bypass vulnerability in the administrative web server. Authentication is not enforced on some administrative functionality when using the "bapply.cgi" endpoint instead of the normal "apply.cgi" endpoint. A remote and unauthenticated can use this vulnerability to modify settings or chain with existing authenticated vulnerabilities. | |
Title | Four-Faith F3x36 bapply.cgi Auth Bypass | |
Weaknesses | CWE-306 CWE-489 |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-02-04T14:58:03.363Z
Updated: 2025-02-04T15:49:20.305Z
Reserved: 2024-10-08T18:08:01.273Z
Link: CVE-2024-9644

Updated: 2025-02-04T15:49:14.364Z

Status : Analyzed
Published: 2025-02-04T15:15:19.273
Modified: 2025-09-19T19:12:31.487
Link: CVE-2024-9644

No data.