CVE-2026-94139: Chengdu Feiyuxing Technology Feiyu Star Router Cookie send_order.cgi command injection
A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. Affected is an unknown function of the file /sendorder.cgi?parameter=loginout of the component Cookie Handler. This manipulation of the argument sessionid causes command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be performed remotely over the network, but the disclosed severity vector indicates that low privileges are required. No user interaction is required.
Which component and input should defenders investigate?
The affected endpoint is /send_order.cgi?parameter=loginout in the Cookie Handler. The vulnerable input is the session_id argument, which can be manipulated to inject commands.
Is public exploit code available?
Yes. The vulnerability information states that an exploit has been publicly disclosed and could be used in attacks.
Is a vendor fix or response available?
No vendor response is reported. The vendor was contacted before disclosure but did not respond.