CVE-2019-12168 is a high-severity remote code execution vulnerability affecting Four-Faith Wireless Mobile Router F3x24 v1.0 devices, specifically through the Command Shell interface. With a CVSS score of 7.2, this flaw allows authenticated attackers to execute arbitrary commands with high impact on confidentiality, integrity, and availability. While no public exploit frameworks like Metasploit or Nuclei are available, media reports confirm active exploitation in the wild, with hackers leveraging it to establish reverse shells. Despite limited community discussion, the vulnerability has garnered significant media coverage, indicating its real-world impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:o:four-faith:f3x24_firmware:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.