Executive brief
The Feiyu Star Router B-MB5E202, a network device used in remote connectivity and management, contains a command injection vulnerability in its web interface. An attacker on the network can manipulate session cookie parameters to execute arbitrary commands on the device, potentially gaining full control of the router and compromising all traffic it handles.
Technical details
The vulnerability exists in the Cookie Handler component of the /send_order.cgi endpoint, where the session_id parameter is inadequately sanitized before being processed. An attacker can inject shell commands through the session_id argument to achieve unauthenticated remote code execution. The vendor has not provided a patch despite early disclosure notification.
Affected products
- Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202 210322-r11656
Timeline
- 2026-09-21: disclosed