Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the affected device.
Unauthenticated attackers over the network can execute arbitrary commands as root on the router, giving them complete control over the device.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
Update the MSI Radix AXE6600 router firmware to a version newer than v781521. Apply the patch available on GitHub (GHSA-fcgq-7m73-rv6c). Additionally, implement network segmentation to restrict access to router management interfaces and disable OpenVPN if not in use.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
NVD published the first details for CVE-2026-71993
A CVSS base score of 9.8 has been assigned.
Feedly found the first article mentioning CVE-2026-71993 . See article
Critical Command Injection Vulnerabilities in MSI Radix AXE6600 Router Firmware
MSI Router Command-Injection Cluster Shows Why Edge Devices Need Exposure Control
CVE Daily Brief — 2026-08-09
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to… (CVE-2026-71993)
CVE-2026-71993 - Exploits & Severity - Feedly
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
