medium · CVSS v3 6.6 · CVSS v4 5.1 · EPSS 0.02055
CVE-2026-94138
Command injection vulnerability in Feiyu Star Router B-MB5E202-210322-r11656 via /send_order.cgi?parameter=del_expmac. Remote attacker can i
Overview
Command injection vulnerability in Feiyu Star Router B-MB5E202-210322-r11656 via /send_order.cgi?parameter=del_expmac. Remote attacker can inject arbitrary commands, enabling full compromise of the device.
Description
A security flaw has been discovered in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. This impacts an unknown function of the file /send_order.cgi?parameter=del_expmac. The manipulation of the argument mac results in command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Impact
Confidentiality: attacker can read sensitive configuration. Integrity: attacker can modify or delete data. Availability: attacker can disrupt router operation. Network administrators and end users of affected routers are at risk.
Remediation
Apply vendor-supplied firmware update that removes command injection. If no patch, disable the /send_order.cgi endpoint or block access via firewall. Ensure router firmware is up-to-date and restrict management interface to local network only.
Risk context
Medium severity (CVSS 6.6) with low EPSS (0.02055). While not highly likely to be targeted, the vulnerability can be exploited remotely and may lead to full device compromise. Defenders should prioritize patching.
Affected products
- Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656
Scores
- Severity
- medium
- CVSS v2
- 5.8
- CVSS v3
- 6.6
- CVSS v4
- 5.1
- EPSS
- 0.02055