Impact
The vulnerability is a command injection flaw triggered by manipulating the session_id parameter in the send_order.cgi endpoint of the Feiyu Star Router’s Cookie Handler component. This flaw allows an attacker to execute arbitrary system commands on the router, weakening confidentiality, integrity, and availability. The weakness maps to CWE‑74 (Command Injection via environment variable) and CWE‑77 (Command Injection via external input).
Affected Systems
The affected product is the Chengdu Feiyuxing Technology Feiyu Star Router B‑MB5E202‑210322‑r11656. The vulnerability resides in an unlabelled function of the /send_order.cgi?parameter=loginout file. No other product versions are listed, so the impact applies to the identified router model and firmware revision.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, but a public exploit has been published. Attackers can remotely reach the vulnerable endpoint via HTTP over the network and, by crafting a malicious session_id value, inject commands. No authentication or additional prerequisites are explicitly mentioned, so the exploitation vector is likely straightforward for anyone with network access to the router’s management interface.
OpenCVE Enrichment