Junglewise Threat Intelligence

CVE-2026-94138: Chengdu Feiyuxing Feiyu Star Router command injection in /send_order.cgi

CVE-2026-94138 · Severity: medium · CVSS 6.6 · Published 2026-09-21

Executive brief

The Feiyu Star Router, a network device used in small office and home networks, contains a command injection vulnerability in its web interface. An attacker can remotely execute arbitrary commands on the router by manipulating parameters sent to the device, potentially allowing full device compromise, network traffic interception, or use as a pivot point for further attacks.

Technical details

A command injection vulnerability exists in the /send_order.cgi endpoint of the Feiyu Star Router, specifically in the mac parameter of the del_expmac function. The vulnerability allows unauthenticated remote code execution through manipulation of the mac argument. The exploit code has been publicly disclosed.

Affected products

  • Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202 210322-r11656

Timeline

  • 2026-09-21: disclosed
  • other: Exploit code released publicly

References

Related threats