Four Faith Four Faith

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Four Faith product.

RSS Feeds for Four Faith security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Four Faith products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Four Faith Sorted by Most Security Vulnerabilities since 2018

Four Faith F3x242 vulnerabilities

Four Faith F3x361 vulnerability

Four Faith F3x36 Firmware1 vulnerability

By the Year

In 2026 there have been 0 vulnerabilities in Four Faith. Last year, in 2025 Four Faith had 2 security vulnerabilities published. Right now, Four Faith is on track to have less security vulnerabilities in 2026 than it did last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 2 9.80
2024 1 7.20
2023 2 9.30

It may take a day or so for new Four Faith vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Four Faith Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2024-9644 Feb 04, 2025
Four-Faith F3x36 v2.0.0 Auth Bypass via bapply.cgi Admin Web Server The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to an authentication bypass vulnerability in the administrative web server. Authentication is not enforced on some administrative functionality when using the "bapply.cgi" endpoint instead of the normal "apply.cgi" endpoint. A remote and unauthenticated can use this vulnerability to modify settings or chain with existing authenticated vulnerabilities.
F3x36 Firmware
CVE-2024-9643 Feb 04, 2025
F3x36 Router v2.0.0 Auth Bypass via HardCoded Credentials The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative web server. An attacker with knowledge of the credentials can gain administrative access via crafted HTTP requests. This issue appears similar to CVE-2023-32645.
F3x24
CVE-2024-12856 Dec 27, 2024
Four-Faith Router OS Command Injection Vulnerability in apply.cgi The Four-Faith router models F3x24 and F3x36 are affected by an operating system (OS) command injection vulnerability. At least firmware version 2.0 allows authenticated and remote attackers to execute arbitrary OS commands over HTTP when modifying the system time via apply.cgi. Additionally, this firmware version has default credentials which, if not changed, would effectively change this vulnerability into an unauthenticated and remote OS command execution issue.
F3x24
F3x36
CVE-2023-6308 Nov 27, 2023
Xiamen Four-Faith Surveillance Sys Unrestricted File Upload via Struts A vulnerability, which was classified as critical, has been found in Xiamen Four-Faith Video Surveillance Management System 2016/2017. Affected by this issue is some unknown functionality of the component Apache Struts. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-246134 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Video Surveillance Management System
CVE-2023-3805 Jul 21, 2023
Xiamen Four Letter Video Surveillance Sys: Improper Auth in Login (Critical) A vulnerability, which was classified as critical, has been found in Xiamen Four Letter Video Surveillance Management System up to 20230712. This issue affects some unknown processing in the library UserInfoAction.class of the component Login. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235073 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Video Surveillance Management System
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.