Chengdu Feiyuxing Technology · Feiyu Star Router · CVE-2026-94139
**Name of the Vulnerable Software and Affected Versions**
Chengdu Feiyuxing Technology Feiyu Star Router version B-MB5E202-210322-r11656
**Description**
An issue exists in the Cookie Handler component where improper handling of the `session id` variable in the '/send order.cgi' endpoint allows for remote command injection. Command injection is a flaw that allows an attacker to execute arbitrary operating system commands on the affected device.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.