Critical Command Injection Vulnerabilities in MSI Radix AXE6600 Router Firmware

Critical Command Injection Vulnerabilities in MSI Radix AXE6600 Router Firmware

First seen 9 Aug 2026, 21:19 UTC Feedlybulwarkblack.comradar.offseq.comwww.incibe.eswww.thehackerwire.com+2 91% similarity 74.0

Article Content

Browse articles
ThreatCluster

MSI Radix AXE6600 router firmware version v781521 has multiple command injection vulnerabilities, identified as CVE-2026-71993, CVE-2026-71992, and CVE-2026-71987. These flaws allow unauthenticated remote attackers to execute arbitrary commands with root privileges by exploiting the openvpn, macfilter, and alg functions. The vulnerabilities have been assigned high CVSS scores of 9.8 and 9.3, indicating severe risks to confidentiality, integrity, and availability. Currently, no public proof-of-concept exploits exist, but the potential for exploitation is significant. Patches are available for some vulnerabilities, and users are advised to restrict access to management interfaces and monitor for suspicious activity. The vulnerabilities were published on August 8 and 9, 2026, with no confirmed exploits reported at this time.

Key Points: • MSI Radix AXE6600 router firmware v781521 has critical command injection vulnerabilities. • Remote attackers can exploit these flaws to gain root access without authentication. • Patches are available for some vulnerabilities; users should restrict access and monitor logs.

ThreatCluster AI How this analysis works

Timeline

2026-08-08
CVE-2026-71992 published
CVE-2026-71992 details a command injection vulnerability in the macfilter function of the MSI Radix AXE6600 router.
Feedly
2026-08-08
CVE-2026-71987 published
CVE-2026-71987 describes a command injection vulnerability in the alg function of the MSI Radix AXE6600 router.
Feedly
2026-08-08
CVE-2026-71984 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-09
CVE-2026-71993 published
CVE-2026-71993 reveals a command injection vulnerability in the openvpn function of the MSI Radix AXE6600 router.
Radar
2026-08-09
Patches released for some vulnerabilities
Patches for CVE-2026-71992 and CVE-2026-71993 are available; users are urged to apply them immediately.
Feedly

Community

Browse all →

Tracked Entities in This Story