PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-94139 Chengdu Feiyuxing Technology CVE debrief

A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. Affected is an unknown function of the file /send_order.cgi?parameter=loginout of the component Cookie Handler. This manipulation of the argument session_id causes command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Defenders should assess exposure and prioritize verification of the /send_order.cgi?parameter=loginout endpoint.

Vendor
Chengdu Feiyuxing Technology
Product
Feiyu Star Router
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-21
Original CVE updated
2026-09-21
Advisory published
2026-09-21
Advisory updated
2026-09-21

Who should care

Defenders responsible for Feiyu Star Router B-MB5E202-210322-r11656 devices should assess exposure and prioritize verification of the /send_order.cgi?parameter=loginout endpoint. They should also review compensating controls for exposed systems while remediation is scheduled and verified, and check relevant monitoring, detection, and logs for exposed assets that need extra review.

Why it matters

CVE-2026-94139 is a command injection vulnerability in Feiyu Star Router B-MB5E202-210322-r11656. Defenders should prioritize verifying exposure, assessing attack feasibility, and monitoring for exploitation attempts.

  • Verify exposure of vulnerable endpoint
  • Assess feasibility of command injection attacks
  • Monitor for potential exploitation attempts
  • Prioritize patching or mitigation for affected devices

Technical summary

The vulnerability is caused by manipulation of the session_id argument in the /send_order.cgi?parameter=loginout endpoint of the Cookie Handler component. This allows for command injection, enabling remote exploitation. The exploit has been made available to the public, and defenders should prioritize verifying exposure of the /send_order.cgi?parameter=loginout endpoint in their inventory, especially for Feiyu Star Router B-MB5E202-210322-r11656 devices. The CVE record and NVD entry provide limited information about the vulnerability.

Defensive priority

Defenders should prioritize verifying exposure of the /send_order.cgi?parameter=loginout endpoint in their inventory, especially for Feiyu Star Router B-MB5E202-210322-r11656 devices.

Recommended defensive actions

  • Verify exposure of the /send_order.cgi?parameter=loginout endpoint in inventory
  • Assess the feasibility of command injection attacks on Feiyu Star Router B-MB5E202-210322-r11656 devices
  • Monitor for potential exploitation attempts
  • Prioritize patching or mitigation for affected devices
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability. The vendor, Chengdu Feiyuxing Technology, did not respond to the disclosure. The exploit has been made available to the public, but there is no information on actual exploitation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-94139 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-94139

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-94139 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94139

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.