<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Chengdu Feiyuxing Technology - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/chengdu-feiyuxing-technology/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 21 Sep 2026 06:26:17 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/chengdu-feiyuxing-technology/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Command Injection in Chengdu Feiyuxing Technology Feiyu Star Router</title><link>https://feed.craftedsignal.io/briefs/2026-09-feiyu-router-rce/</link><pubDate>Mon, 21 Sep 2026 06:26:17 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-feiyu-router-rce/</guid><description>An unauthenticated remote command injection vulnerability (CVE-2026-94139) in the Cookie Handler component of Feiyu Star Router allows attackers to execute arbitrary system commands via a manipulated session_id argument.</description><content:encoded><![CDATA[<p>A critical command injection vulnerability exists within the Cookie Handler component of the Chengdu Feiyuxing Technology Feiyu Star Router (B-MB5E202-210322-r11656). The flaw resides in the processing logic of the '/send_order.cgi?parameter=loginout' endpoint, specifically failing to sanitize the 'session_id' parameter. An unauthenticated remote attacker can exploit this weakness by injecting shell metacharacters into the 'session_id' argument, leading to arbitrary command execution with the privileges of the web service.</p>
<p>Publicly available exploit code has been identified, increasing the risk of active exploitation. Despite attempts to notify the vendor, no security patches or remediations have been issued. The vulnerability is highly relevant for defenders as it allows for trivial remote code execution on edge network devices, potentially facilitating lateral movement, device takeover, or traffic interception within the target environment. Given the lack of a vendor patch, organizations should consider isolating these devices or restricting access to the management interface.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation grants an attacker full remote code execution on the router, which typically acts as a gateway for the network. This provides an entry point for further compromise of internal systems, traffic monitoring, or persistent backdoor installation within the network infrastructure.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams:</p>
<ul>
<li>Isolate affected Feiyu Star Router units from the public internet immediately to prevent unauthenticated access to '/send_order.cgi'.</li>
<li>Implement ingress filtering on the perimeter firewall to restrict access to the web management interface of these devices to known, trusted administrative IP addresses.</li>
<li>Monitor logs for HTTP requests directed at '/send_order.cgi?parameter=loginout' containing shell-sensitive characters (e.g., ;, |, &amp;, $, `) in the session_id parameter.</li>
<li>Since the vendor has not provided a patch for CVE-2026-94139, evaluate replacement options if the device cannot be adequately secured through network segmentation.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>vulnerability</category><category>remote-code-execution</category><category>network-security</category></item></channel></rss>