Sceawere

Vulnerability Detail

CVE-2026-94139UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Feiyu Star Router Command Injection

Vulnerability Metadata

Severity
High
Score / CVSS
7.4
Creation Date
2h ago
Vendor
Chengdu Feiyuxing Technology
Product
Feiyu Star Router
Attack Type
Command Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. Affected is an unknown function of the file /send_order.cgi?parameter=loginout of the component Cookie Handler. This manipulation of the argument session_id causes command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.4",
  "pubDate": "2026-09-21T05:16:41.857Z",
  "pubdate": "2026-09-21T05:16:41.857Z",
  "executiveSummary": "A critical command injection vulnerability exists in the Chengdu Feiyuxing Technology Feiyu Star Router (version B-MB5E202-210322-r11656) within the Cookie Handler component.\nThe vulnerability is located in the /send_order.cgi?parameter=loginout script, where improper input sanitization of the session_id argument allows an attacker to inject arbitrary system commands.\nSuccessful exploitation permits an unauthenticated or remote attacker to execute system-level commands with the privileges of the underlying web service process.\nThe impact includes full device compromise, potential unauthorized network access, and persistent backdoor installation.\nGiven that public exploit code is available and the vendor has remained unresponsive to disclosure attempts, the risk to affected devices is classified as critical.\nThe vulnerability does not require complex prerequisites, as the attack can be executed remotely via crafted HTTP requests targeting the vulnerable CGI interface.",
  "technicalDetails": "The vulnerability originates from a failure to validate or sanitize the session_id parameter processed by the /send_order.cgi script when handling logout requests (parameter=loginout).\nThe Cookie Handler component appears to pass the session_id value directly to a system shell execution function without sufficient neutralization of shell metacharacters.\nThe attack flow begins when an attacker sends a specifically crafted HTTP request to the device's web management interface. By injecting command separators (e.g., ;, &&, or |) into the session_id argument, the attacker can break out of the intended application context and append arbitrary shell commands.\nUpon receipt of the malicious request, the web server executes the injected payload with the permissions assigned to the web daemon. Because these routers often run services with elevated or root privileges, the attacker can gain complete control over the device's operating system.\nThe exploitation process does not require prior authentication, allowing remote attackers to trigger the vulnerability simply by reaching the exposed management port. The payload behavior typically involves executing commands such as binary execution, file system manipulation, or the initiation of reverse shells to provide persistent remote access.\nThe technical root cause is a lack of input validation and the use of dangerous system-level APIs (such as popen or system) within the CGI environment. Because the affected version (B-MB5E202-210322-r11656) lacks input filtering, it is inherently susceptible to command injection.\nPost-exploitation, an attacker can modify device configuration, intercept or redirect network traffic passing through the router, or pivot into the internal network protected by the device. The availability of public exploits significantly lowers the barrier to entry, enabling automated and wide-scale exploitation by malicious actors.\nWithout vendor intervention or firmware patches, the attack surface remains open to anyone with network connectivity to the device's administrative interface."
}
CVE-2026-94139: Feiyu Star Router Command Injection (HIGH Severity, CVSS: 7.4) | Sceawere