CVE-2026-71993

MSI · Radix AXE6600

The MSI Radix AXE6600 router firmware contains a command injection vulnerability in the openvpn and macfilter functions, allowing unauthenticated remote attackers to execute arbitrary system commands.

Executive summary

A critical command injection vulnerability in the MSI Radix AXE6600 router allows unauthenticated remote attackers to gain full root-level control over the device.

Vulnerability

This is an OS command injection flaw (CWE-78) triggered via the openvpn and macfilter functions. The vulnerability is exploitable by unauthenticated remote attackers, as indicated by the CVSS vector AV:N/PR:N.

Business impact

The ability to execute arbitrary commands with root privileges grants an attacker complete control over the networking equipment. This presents a severe risk of data interception, persistent network-level backdoors, and total loss of confidentiality, integrity, and availability. With a CVSS score of 9.8, this flaw constitutes a critical risk that could lead to the compromise of the entire internal network.

Remediation

Immediate Action: Users should visit the official MSI support website to check for firmware updates and apply the latest available version immediately.

Proactive Monitoring: Monitor device logs for unusual access patterns, unexpected process execution, or configuration changes initiated via the OpenVPN or MAC filter settings.

Compensating Controls: Disable remote management interfaces, restrict administrative access to a trusted internal network, and ensure the device is not directly exposed to the public internet where possible.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical nature of this vulnerability and the potential for total device takeover, administrators must prioritize the application of firmware updates. If an update is not yet available, strictly isolate the device from external network exposure to prevent remote exploitation.