Command Injection Vulnerability in Feiyu Star Router by Chengdu Feiyuxing Technology
CVE-2026-94139
5.3MEDIUM
What is CVE-2026-94139?
A command injection vulnerability has been discovered in the cookie handler functionality of the Feiyu Star Router B-MB5E202-210322-r11656. Specifically, the issue arises when the session_id parameter within the /send_order.cgi endpoint is manipulated. This flaw allows attackers to execute arbitrary commands remotely, posing a significant risk to the integrity and security of the device. Despite early notification to the vendor, there has been no response or indication of a fix, leaving users vulnerable to potential exploitation.
Affected Version(s)
Feiyu Star Router B-MB5E202-210322-r11656
