CVE-2026-71993
MSI · Radix AXE6600
The MSI Radix AXE6600 router firmware contains a command injection vulnerability in the openvpn and macfilter functions, allowing unauthenticated remote attackers to execute arbitrary system commands.
Executive summary
A critical command injection vulnerability in the MSI Radix AXE6600 router allows unauthenticated remote attackers to gain full root-level control over the device.
Vulnerability
This is an OS command injection flaw (CWE-78) triggered via the openvpn and macfilter functions. The vulnerability is exploitable by unauthenticated remote attackers, as indicated by the CVSS vector AV:N/PR:N.
Business impact
The ability to execute arbitrary commands with root privileges grants an attacker complete control over the networking equipment. This presents a severe risk of data interception, persistent network-level backdoors, and total loss of confidentiality, integrity, and availability. With a CVSS score of 9.8, this flaw constitutes a critical risk that could lead to the compromise of the entire internal network.
Remediation
Immediate Action: Users should visit the official MSI support website to check for firmware updates and apply the latest available version immediately.
Proactive Monitoring: Monitor device logs for unusual access patterns, unexpected process execution, or configuration changes initiated via the OpenVPN or MAC filter settings.
Compensating Controls: Disable remote management interfaces, restrict administrative access to a trusted internal network, and ensure the device is not directly exposed to the public internet where possible.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical nature of this vulnerability and the potential for total device takeover, administrators must prioritize the application of firmware updates. If an update is not yet available, strictly isolate the device from external network exposure to prevent remote exploitation.