PatchSiren

Chengdu Feiyuxing Technology CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Chengdu Feiyuxing Technology CVE published 2026-09-21

CVE-2026-94139

A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. Affected is an unknown function of the file /send_order.cgi?parameter=loginout of the component Cookie Handler. This manipulation of the argument session_id causes command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for [truncated]

LOW Chengdu Feiyuxing Technology CVE published 2026-09-21

CVE-2026-94138

A security flaw has been discovered in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. This impacts an unknown function of the file /send_order.cgi?parameter=del_expmac. The manipulation of the argument mac results in command injection. The attack may be launched remotely. The vulnerability is caused by improper handling of the mac argument, allowing for command injection attacks. [truncated]