Junglewise Threat Intelligence

CVE-2026-94139: Chengdu Feiyuxing Feiyu Star Router B-MB5E202 command injection in cookie handler

CVE-2026-94139 · Severity: high · CVSS 7.4 · Published 2026-09-21

Executive brief

The Feiyu Star Router B-MB5E202, a network device used in remote connectivity and management, contains a command injection vulnerability in its web interface. An attacker on the network can manipulate session cookie parameters to execute arbitrary commands on the device, potentially gaining full control of the router and compromising all traffic it handles.

Technical details

The vulnerability exists in the Cookie Handler component of the /send_order.cgi endpoint, where the session_id parameter is inadequately sanitized before being processed. An attacker can inject shell commands through the session_id argument to achieve unauthenticated remote code execution. The vendor has not provided a patch despite early disclosure notification.

Affected products

  • Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202 210322-r11656

Timeline

  • 2026-09-21: disclosed

References

Related threats