PatchSiren cyber security CVE debrief
CVE-2026-94138 Chengdu Feiyuxing Technology CVE debrief
A security flaw has been discovered in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. This impacts an unknown function of the file /send_order.cgi?parameter=del_expmac. The manipulation of the argument mac results in command injection. The attack may be launched remotely. The vulnerability is caused by improper handling of the mac argument, allowing for command injection attacks. Network administrators and security teams should verify and apply vendor patches or updates if available, restrict access to the /send_order.cgi endpoint, and monitor for suspicious activity.
- Vendor
- Chengdu Feiyuxing Technology
- Product
- Feiyu Star Router
- CVSS
- LOW 2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-21
- Original CVE updated
- 2026-09-21
- Advisory published
- 2026-09-21
- Advisory updated
- 2026-09-21
Who should care
Network administrators and security teams responsible for managing and securing Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656 devices. They should verify and apply vendor patches or updates if available, restrict access to the /send_order.cgi endpoint, and monitor for suspicious activity. They should also review compensating controls for exposed systems while remediation is scheduled and verified, and check relevant monitoring,
Why it matters
CVE-2026-94138 is a command injection vulnerability in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. Network administrators and security teams should verify and apply vendor patches or updates if available, restrict access to the /send_order.cgi endpoint, and monitor for suspicious activity.
- Remote attackers may be able to inject malicious commands
- Verify and apply vendor patches or updates if available
- Restrict access to the /send_order.cgi endpoint
Technical summary
The vulnerability is located in the /send_order.cgi file and is caused by improper handling of the mac argument, allowing for command injection attacks. The attack may be launched remotely. The vulnerability has been publicly disclosed and may be used for attacks. Network administrators and security teams should verify and apply vendor patches or updates if available, restrict access to the /send_order.cgi endpoint, and monitor for suspicious activity. The affected product is Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656.
Defensive priority
Verify and apply vendor patches or updates if available; restrict access to the /send_order.cgi endpoint; monitor for suspicious activity
Recommended defensive actions
- Verify and apply vendor patches or updates if available
- Restrict access to the /send_order.cgi endpoint
- Monitor for suspicious activity
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. The vendor was contacted but did not respond. The vulnerability has been publicly disclosed and may be used for attacks. There is no information on known affected scope or source-confidence limits. Defenders should verify the existence of affected product deployments in managed environments and review official advisories or CVE records to validate affected scope, severity, and vendor guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-94138 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-94138
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-94138 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94138
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-94138
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/893913
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/408055
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/408055/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.