CVE-2026-94139 | Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656 Cookie send_order.cgi?parameter=loginout session_id command injection

SecurityVulns

A vulnerability marked as critical has been reported in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. Affected is an unknown function of the file /send_order.cgi?parameter=loginout of the component Cookie Handler. This manipulation of the argument session_id causes command injection.

This vulnerability is registered as CVE-2026-94139. Remote exploitation of the attack is possible. Furthermore, an exploit is available.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More