Executive brief
The Feiyu Star Router, a network device used in small office and home networks, contains a command injection vulnerability in its web interface. An attacker can remotely execute arbitrary commands on the router by manipulating parameters sent to the device, potentially allowing full device compromise, network traffic interception, or use as a pivot point for further attacks.
Technical details
A command injection vulnerability exists in the /send_order.cgi endpoint of the Feiyu Star Router, specifically in the mac parameter of the del_expmac function. The vulnerability allows unauthenticated remote code execution through manipulation of the mac argument. The exploit code has been publicly disclosed.
Affected products
- Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202 210322-r11656
Timeline
- 2026-09-21: disclosed
- other: Exploit code released publicly