Product
An unauthenticated remote command injection vulnerability (CVE-2026-94139) in the Cookie Handler component of Feiyu Star Router allows attackers to execute arbitrary system commands via a manipulated session_id argument.