Critical Command Injection Vulnerabilities in MSI Radix AXE6600 Router Firmware
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
MSI Radix AXE6600 router firmware version v781521 has multiple command injection vulnerabilities, identified as CVE-2026-71993, CVE-2026-71992, and CVE-2026-71987. These flaws allow unauthenticated remote attackers to execute arbitrary commands with root privileges by exploiting the openvpn, macfilter, and alg functions. The vulnerabilities have been assigned high CVSS scores of 9.8 and 9.3, indicating severe risks to confidentiality, integrity, and availability. Currently, no public proof-of-concept exploits exist, but the potential for exploitation is significant. Patches are available for some vulnerabilities, and users are advised to restrict access to management interfaces and monitor for suspicious activity. The vulnerabilities were published on August 8 and 9, 2026, with no confirmed exploits reported at this time.
Key Points: • MSI Radix AXE6600 router firmware v781521 has critical command injection vulnerabilities. • Remote attackers can exploit these flaws to gain root access without authentication. • Patches are available for some vulnerabilities; users should restrict access and monitor logs.