Description
A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. Affected is an unknown function of the file /send_order.cgi?parameter=loginout of the component Cookie Handler. This manipulation of the argument session_id causes command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-21
Score: 5.3 Medium
EPSS: 1.2% Low
KEV: No
Impact: Remote Command Execution
Action: Patch Now
AI Analysis

Impact

The vulnerability is a command injection flaw triggered by manipulating the session_id parameter in the send_order.cgi endpoint of the Feiyu Star Router’s Cookie Handler component. This flaw allows an attacker to execute arbitrary system commands on the router, weakening confidentiality, integrity, and availability. The weakness maps to CWE‑74 and CWE‑77.

Affected Systems

The affected product is the Chengdu Feiyuxing Technology Feiyu Star Router B‑MB5E202‑210322‑r11656. The vulnerability resides in an unlabelled function of the /send_order.cgi?parameter=loginout file. No other product versions are listed, so the impact applies to the identified router model and firmware revision.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score of 1% indicates a low but nonzero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, but a public exploit has been published. Attackers can remotely reach the vulnerable endpoint via HTTP over the network and, by crafting a malicious session_id value, inject commands. No authentication or additional prerequisites are explicitly mentioned, so the exploitation vector is likely straightforward for anyone with network access to the router’s management interface.

Generated by OpenCVE AI on September 21, 2026 at 15:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any vendor update that addresses the command injection in the /send_order.cgi interface
  • Block external access to the router’s /send_order.cgi endpoint using firewall rules or access control lists
  • Implement network segmentation to limit the router’s exposure to untrusted networks and enforce strong administrative credentials

Generated by OpenCVE AI on September 21, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. Affected is an unknown function of the file /send_order.cgi?parameter=loginout of the component Cookie Handler. This manipulation of the argument session_id causes command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title Chengdu Feiyuxing Technology Feiyu Star Router Cookie send_order.cgi command injection
First Time appeared Chengdu Feiyuxing Technology
Chengdu Feiyuxing Technology feiyu Star Router
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:h:chengdu_feiyuxing_technology:feiyu_star_router:*:*:*:*:*:*:*:*
Vendors & Products Chengdu Feiyuxing Technology
Chengdu Feiyuxing Technology feiyu Star Router
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P'}


Subscriptions

Chengdu Feiyuxing Technology Feiyu Star Router
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-22T15:41:29.651Z

Reserved: 2026-09-20T19:38:24.231Z

Link: CVE-2026-94139

cve-icon Vulnrichment

Updated: 2026-09-22T15:30:10.351Z

cve-icon NVD

Status : Deferred

Published: 2026-09-21T05:16:41.857

Modified: 2026-09-22T16:18:17.467

Link: CVE-2026-94139

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T15:30:16Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')