Command Injection Vulnerability in Chengdu Feiyuxing Technology Feiyu Star Router
CVE-2026-94138
Key Information:
- Vendor
Chengdu Feiyuxing Technology
- Status
- Vendor
- CVE Published:
- 21 September 2026
Badges
What is CVE-2026-94138?
A command injection vulnerability exists in the Feiyu Star Router B-MB5E202-210322-r11656, specifically within the /send_order.cgi?parameter=del_expmac endpoint. By manipulating the 'mac' argument, attackers can execute arbitrary commands on the device remotely. This flaw could lead to significant security risks, particularly since the vendor has not provided any acknowledgment or response regarding this issue. Exploits for this vulnerability have been publicly disclosed, making it critical for users to address this security flaw promptly.
Affected Version(s)
Feiyu Star Router B-MB5E202-210322-r11656
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
