← Back to the live CVE advisory feed

CVE-2026-94138: Feiyu Star Router

Severity
2 (LOW)
Vendor
CHENGDU FEIYUXING TECHNOLOGY
Affected versions
B-MB5E202-210322-r11656
Patch status
Unknown
Published
2026-09-21T04:17:37.083
Modified
2026-09-21T04:17:37.083

Why it matters

Vulnerability requiring standard triage and vendor validation.

Recommended admin actions

  • Review during normal vulnerability triage unless the affected system is internet-facing or business-critical.
  • Treat internet-facing systems as higher priority.

Technical summary

A security flaw has been discovered in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. This impacts an unknown function of the file /send_order.cgi?parameter=del_expmac. The manipulation of the argument mac results in command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: SEP 21, 2026 08:00 AM UTC
91 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-90817
REDCap PATCH
Reporter: CONTACT
9.8
CRITICAL
VIEW RECORD
CVE-2026-88856
OrdaSoft Joomla Gallery free extension for Joomla
Reporter: SECURITY
9.4
CRITICAL
VIEW RECORD
CVE-2026-88857
OrdaSoft Joomla Gallery free extension for Joomla
Reporter: SECURITY
9.4
CRITICAL
VIEW RECORD
CVE-2026-94003
CF-N1-S
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-88854
OrdaSoft Joomla Gallery free extension for Joomla
Reporter: SECURITY
9.3
CRITICAL
VIEW RECORD
CVE-2026-94089
DIR-868L
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-94097
NBR200V2
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-94107
nivocart
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-94104
nivocart
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94106
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94109
openEQUELLA PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-88855
OrdaSoft Joomla Gallery free extension for Joomla
Reporter: SECURITY
8.6
HIGH
VIEW RECORD
CVE-2026-94095
NBR200V2
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-94096
NBR200V2
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-94099
NBR200V2
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-94100
NBR200V2
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-94101
NBR200V2
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-94098
NBR200V2
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-94128
VIVID LED DJ
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-94129
VALKYRIE AURORA
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-94142
Temperature Monitor Utility
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-94146
BIOS Update Utility
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-94108
Product identification pending PATCH
Reporter: DISCLOSURE
8.3
HIGH
VIEW RECORD
CVE-2026-94112
ezBookkeeping PATCH
Reporter: DISCLOSURE
7.6
HIGH
VIEW RECORD
CVE-2026-94036
DIR-X1860
Reporter: CNA
7.4
HIGH
VIEW RECORD
CVE-2026-94113
ERPNext PATCH
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-90860
Canva
Reporter: 61ADB53E-E4B3-47F7-8A93-4717C9E77DC6
7.1
HIGH
VIEW RECORD
CVE-2026-93970
SxDevOps
Reporter: CNA
6.9
MEDIUM
VIEW RECORD
CVE-2026-93971
SxDevOps
Reporter: CNA
6.9
MEDIUM
VIEW RECORD
CVE-2026-94105
Product identification pending
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-94111
Product identification pending
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-92254
Anti-Virus
Reporter: 34EDF4F2-2577-40AB-82CE-39F45972C129
6.9
MEDIUM
VIEW RECORD
CVE-2026-94185
Product identification pending PATCH
Reporter: 7FFCEE3D-2C14-4C3E-B844-86C6A321A158
6.7
MEDIUM
VIEW RECORD
CVE-2026-86555
Product identification pending
Reporter: PSIRT
6.2
MEDIUM
VIEW RECORD
CVE-2026-92252
Anti-Virus
Reporter: 34EDF4F2-2577-40AB-82CE-39F45972C129
5.9
MEDIUM
VIEW RECORD
CVE-2026-93972
Online Reviewer Management System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-93973
Online Reviewer Management System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-93974
Online Reviewer Management System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-93978
Internship Management System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-93979
Internship Management System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-93980
Internship Management System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-93997
Drug Recommendation System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-94004
DedeCMS
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-94015
Drug Recommendation System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-94038
dim-sum-app
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-94039
TaxHacker
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-94040
TaxHacker
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-94043
Free5GC
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-94044
MCP
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-94110
QCMS
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-94143
drogon
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-94144
drogon
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-94215
Product identification pending
Reporter: SECALERT
5.5
MEDIUM
VIEW RECORD
CVE-2026-94050
DIR-X1860Z PATCH
Reporter: CNA
5.3
MEDIUM
VIEW RECORD
CVE-2026-94090
Manalyze
Reporter: CNA
5.3
MEDIUM
VIEW RECORD
CVE-2026-92253
Anti-Virus
Reporter: 34EDF4F2-2577-40AB-82CE-39F45972C129
5.2
MEDIUM
VIEW RECORD
CVE-2026-94213
Product identification pending
Reporter: SECALERT
4.9
MEDIUM
VIEW RECORD
CVE-2026-86554
Product identification pending
Reporter: PSIRT
4.3
MEDIUM
VIEW RECORD
CVE-2026-94217
Product identification pending
Reporter: SECALERT
3.5
LOW
VIEW RECORD
CVE-2026-94218
Product identification pending
Reporter: SECALERT
3.1
LOW
VIEW RECORD
CVE-2026-94028
Mealie PATCH
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-94031
nexus-mcp
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-94032
Leave Management System
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-94035
Drug Recommendation System
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-94037
mcp-file-analyzer
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-94041
Restaurant-Management-System
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-94042
Restaurant Management System
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-94046
ACE-MCP
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-94047
MCPHub PATCH
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-94049
slideshot
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-94051
cowork_bench
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-94093
stable-baselines3
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-94094
OpenClaw
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-94102
WuzhiCMS
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-94139
Feiyu Star Router
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-93977
Assessment Management
Reporter: CNA
2
LOW
VIEW RECORD
CVE-2026-94033
Drug Recommendation System
Reporter: CNA
2
LOW
VIEW RECORD
CVE-2026-94034
Drug Recommendation System
Reporter: CNA
2
LOW
VIEW RECORD
CVE-2026-94045
newbee-mall
Reporter: CNA
2
LOW
VIEW RECORD
CVE-2026-94048
QR Code Attendance Management System
Reporter: CNA
2
LOW
VIEW RECORD
CVE-2026-94091
gensim
Reporter: CNA
2
LOW
VIEW RECORD
CVE-2026-94092
dgl
Reporter: CNA
2
LOW
VIEW RECORD
CVE-2026-94103
RooCMS
Reporter: CNA
2
LOW
VIEW RECORD
CVE-2026-94138
Feiyu Star Router
Reporter: CNA
2
LOW
VIEW RECORD
CVE-2026-94145
xxl-job
Reporter: CNA
2
LOW
VIEW RECORD
CVE-2026-93975
Assessment Management
Reporter: CNA
1.9
LOW
VIEW RECORD
CVE-2026-93976
Assessment Management
Reporter: CNA
1.9
LOW
VIEW RECORD
CVE-2026-94016
Drug Recommendation System
Reporter: CNA
1.9
LOW
VIEW RECORD
CVE-2026-94137
shzh
Reporter: CNA
1.9
LOW
VIEW RECORD
CVE-2026-94030
SerenityOS
Reporter: CNA
1.3
LOW
VIEW RECORD
CVE-2026-82187
Web to Print Online Designer PATCH
Reporter: CONTACT
0
N/A
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.