Description
A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. Affected is an unknown function of the file /send_order.cgi?parameter=loginout of the component Cookie Handler. This manipulation of the argument session_id causes command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-21
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Remote Command Execution
Action: Patch Now
AI Analysis

Impact

The vulnerability is a command injection flaw triggered by manipulating the session_id parameter in the send_order.cgi endpoint of the Feiyu Star Router’s Cookie Handler component. This flaw allows an attacker to execute arbitrary system commands on the router, weakening confidentiality, integrity, and availability. The weakness maps to CWE‑74 (Command Injection via environment variable) and CWE‑77 (Command Injection via external input).

Affected Systems

The affected product is the Chengdu Feiyuxing Technology Feiyu Star Router B‑MB5E202‑210322‑r11656. The vulnerability resides in an unlabelled function of the /send_order.cgi?parameter=loginout file. No other product versions are listed, so the impact applies to the identified router model and firmware revision.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, but a public exploit has been published. Attackers can remotely reach the vulnerable endpoint via HTTP over the network and, by crafting a malicious session_id value, inject commands. No authentication or additional prerequisites are explicitly mentioned, so the exploitation vector is likely straightforward for anyone with network access to the router’s management interface.

Generated by OpenCVE AI on September 21, 2026 at 05:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor update that addresses the command injection in the /send_order.cgi interface
  • Block external access to the router’s /send_order.cgi endpoint using firewall rules or access control lists
  • Implement network segmentation to limit the router’s exposure to untrusted networks and enforce strong administrative credentials

Generated by OpenCVE AI on September 21, 2026 at 05:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. Affected is an unknown function of the file /send_order.cgi?parameter=loginout of the component Cookie Handler. This manipulation of the argument session_id causes command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title Chengdu Feiyuxing Technology Feiyu Star Router Cookie send_order.cgi command injection
First Time appeared Chengdu Feiyuxing Technology
Chengdu Feiyuxing Technology feiyu Star Router
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:h:chengdu_feiyuxing_technology:feiyu_star_router:*:*:*:*:*:*:*:*
Vendors & Products Chengdu Feiyuxing Technology
Chengdu Feiyuxing Technology feiyu Star Router
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P'}


Subscriptions

Chengdu Feiyuxing Technology Feiyu Star Router
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-21T04:30:35.728Z

Reserved: 2026-09-20T19:38:24.231Z

Link: CVE-2026-94139

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-21T05:16:41.857

Modified: 2026-09-21T05:16:41.857

Link: CVE-2026-94139

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:30:07Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')