rootpwn

high · CVSS v3 7.4 · CVSS v4 5.3 · EPSS 0.01158

CVE-2026-94139

A command injection flaw exists in the Cookie Handler of Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656 via the /sen

Overview

A command injection flaw exists in the Cookie Handler of Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656 via the /send_order.cgi?parameter=loginout endpoint. Attackers can remotely inject OS commands by manipulating the session_id parameter. The vulnerability is publicly exploitable and the vendor has not released a fix.

Description

A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. Affected is an unknown function of the file /send_order.cgi?parameter=loginout of the component Cookie Handler. This manipulation of the argument session_id causes command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Impact

Confidentiality: attackers can read or modify router configuration. Integrity: arbitrary commands can be executed, potentially altering firmware or network settings. Availability: the router may become unresponsive or reboot. Network administrators and end users of affected routers are at risk.

Remediation

1. Apply the vendor’s firmware update once released. 2. If no patch is available, disable remote management or block access to /send_order.cgi via firewall or ACL. 3. Restrict the session_id parameter to alphanumeric values and enforce input validation. 4. Monitor logs for anomalous command execution patterns.

Risk context

The vulnerability is rated high with a CVSS v3 score of 7.4 and an EPSS of 0.01158, indicating a moderate likelihood of exploitation. Immediate action is advised to mitigate potential remote command execution.

Affected products

  • Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656

Scores

Severity
high
CVSS v2
6.5
CVSS v3
7.4
CVSS v4
5.3
EPSS
0.01158

command-injection router remote-exploitation firmware network-security high-severity EPSS

← All CVEs