Impact
The vulnerability is a command injection caused by inadequate validation of the "mac" argument in the send_order.cgi interface. By manipulating this parameter, an attacker can execute arbitrary shell commands on the router, potentially achieving full compromise of the device. This flaw represents a classic command injection weakness (CWE‑74) combined with improper input validation (CWE‑77).
Affected Systems
Chengdu Feiyuxing Technology’s Feiyu Star Router model B‑MB5E202‑210322‑r11656 is affected; no other firmware or variant versions are indicated, which implies any device running that exact firmware or containing the vulnerable component may be at risk.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity, and EPSS data is unavailable, so the exploitation probability cannot be precisely quantified. The vulnerability is not listed in CISA KEV, but public exploit releases raise concern. The likely attack vector is remote over HTTP, with an attacker able to trigger the injection by sending a crafted request to /send_order.cgi’s mac parameter from an allowed network.
OpenCVE Enrichment