Command Injection Vulnerability in Feiyu Star Router by Chengdu Feiyuxing Technology
CVE-2026-94139

5.3MEDIUM

Key Information:

Vendor
CVE Published:
21 September 2026

What is CVE-2026-94139?

A command injection vulnerability has been discovered in the cookie handler functionality of the Feiyu Star Router B-MB5E202-210322-r11656. Specifically, the issue arises when the session_id parameter within the /send_order.cgi endpoint is manipulated. This flaw allows attackers to execute arbitrary commands remotely, posing a significant risk to the integrity and security of the device. Despite early notification to the vendor, there has been no response or indication of a fix, leaving users vulnerable to potential exploitation.

Affected Version(s)

Feiyu Star Router B-MB5E202-210322-r11656

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

liyunpeng (VulDB User)
VulDB CNA Team
.