PatchSiren cyber security CVE debrief
CVE-2026-94139 Chengdu Feiyuxing Technology CVE debrief
A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. Affected is an unknown function of the file /send_order.cgi?parameter=loginout of the component Cookie Handler. This manipulation of the argument session_id causes command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Defenders should assess exposure and prioritize verification of the /send_order.cgi?parameter=loginout endpoint.
- Vendor
- Chengdu Feiyuxing Technology
- Product
- Feiyu Star Router
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-21
- Original CVE updated
- 2026-09-21
- Advisory published
- 2026-09-21
- Advisory updated
- 2026-09-21
Who should care
Defenders responsible for Feiyu Star Router B-MB5E202-210322-r11656 devices should assess exposure and prioritize verification of the /send_order.cgi?parameter=loginout endpoint. They should also review compensating controls for exposed systems while remediation is scheduled and verified, and check relevant monitoring, detection, and logs for exposed assets that need extra review.
Why it matters
CVE-2026-94139 is a command injection vulnerability in Feiyu Star Router B-MB5E202-210322-r11656. Defenders should prioritize verifying exposure, assessing attack feasibility, and monitoring for exploitation attempts.
- Verify exposure of vulnerable endpoint
- Assess feasibility of command injection attacks
- Monitor for potential exploitation attempts
- Prioritize patching or mitigation for affected devices
Technical summary
The vulnerability is caused by manipulation of the session_id argument in the /send_order.cgi?parameter=loginout endpoint of the Cookie Handler component. This allows for command injection, enabling remote exploitation. The exploit has been made available to the public, and defenders should prioritize verifying exposure of the /send_order.cgi?parameter=loginout endpoint in their inventory, especially for Feiyu Star Router B-MB5E202-210322-r11656 devices. The CVE record and NVD entry provide limited information about the vulnerability.
Defensive priority
Defenders should prioritize verifying exposure of the /send_order.cgi?parameter=loginout endpoint in their inventory, especially for Feiyu Star Router B-MB5E202-210322-r11656 devices.
Recommended defensive actions
- Verify exposure of the /send_order.cgi?parameter=loginout endpoint in inventory
- Assess the feasibility of command injection attacks on Feiyu Star Router B-MB5E202-210322-r11656 devices
- Monitor for potential exploitation attempts
- Prioritize patching or mitigation for affected devices
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. The vendor, Chengdu Feiyuxing Technology, did not respond to the disclosure. The exploit has been made available to the public, but there is no information on actual exploitation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-94139 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-94139
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-94139 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94139
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-94139
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/893914
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/408056
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/408056/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.