rootpwn

medium · CVSS v3 6.6 · CVSS v4 5.1 · EPSS 0.02055

CVE-2026-94138

Command injection vulnerability in Feiyu Star Router B-MB5E202-210322-r11656 via /send_order.cgi?parameter=del_expmac. Remote attacker can i

Overview

Command injection vulnerability in Feiyu Star Router B-MB5E202-210322-r11656 via /send_order.cgi?parameter=del_expmac. Remote attacker can inject arbitrary commands, enabling full compromise of the device.

Description

A security flaw has been discovered in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. This impacts an unknown function of the file /send_order.cgi?parameter=del_expmac. The manipulation of the argument mac results in command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Impact

Confidentiality: attacker can read sensitive configuration. Integrity: attacker can modify or delete data. Availability: attacker can disrupt router operation. Network administrators and end users of affected routers are at risk.

Remediation

Apply vendor-supplied firmware update that removes command injection. If no patch, disable the /send_order.cgi endpoint or block access via firewall. Ensure router firmware is up-to-date and restrict management interface to local network only.

Risk context

Medium severity (CVSS 6.6) with low EPSS (0.02055). While not highly likely to be targeted, the vulnerability can be exploited remotely and may lead to full device compromise. Defenders should prioritize patching.

Affected products

  • Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656

Scores

Severity
medium
CVSS v2
5.8
CVSS v3
6.6
CVSS v4
5.1
EPSS
0.02055

command-injection router remote-execution firmware network-security

← All CVEs