CVE-2026-71992

MSI · Radix AXE6600

A command injection vulnerability in the macfilter function of the MSI Radix AXE6600 router allows unauthenticated remote attackers to execute arbitrary system commands with root privileges.

Executive summary

The MSI Radix AXE6600 router contains a critical command injection vulnerability in its macfilter function, allowing unauthenticated remote attackers to gain root-level control.

Vulnerability

This is an OS command injection vulnerability (CWE-78) triggered through the macfilter configuration function. The vulnerability is unauthenticated and allows attackers to craft malicious input parameters that bypass validation, leading to arbitrary command execution as the root user.

Business impact

The CVSS score of 9.8 underscores the severity of this issue. An attacker exploiting this flaw can gain complete control over the network gateway, enabling them to manipulate network traffic, bypass security policies, and potentially gain unauthorized access to internal resources, leading to severe operational and security consequences.

Remediation

Immediate Action: Update the firmware of the MSI Radix AXE6600 to the latest version made available by the vendor.

Proactive Monitoring: Audit device configuration changes and monitor for unexpected system commands or processes related to the macfilter function.

Compensating Controls: Implement strict access controls for the router management interface and verify that security settings are not being modified by unauthorized parties.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical severity and the potential for total system compromise, immediate remediation is required. Administrators should verify their current firmware version and apply the vendor patch as soon as possible to protect the network environment.