Description
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system.
Published: 2026-08-08
Score: 9.3 Critical
EPSS: 1.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The MSI Radix AXE6600 firmware version v781521 contains a CWE‑78 command injection flaw in the macfilter function, allowing a remote attacker to inject and execute arbitrary operating‑system commands on the device. This escalates privileges to root, granting full control over the router’s underlying system and enabling attackers to modify traffic, install persistence mechanisms, or compromise connected devices.

Affected Systems

MSI Radix AXE6600 WiFi 6E Tri‑Band Gaming Router running firmware version v781521 is affected. No other firmware revisions are listed as vulnerable in the CNA data.

Risk and Exploitability

The CVSS score of 9.3 indicates the vulnerability is severe, with the potential for complete system takeover. The EPSS score of 1% indicates a very small but non-zero probability of exploitation, and the vulnerability is not listed in CISA KEV, suggesting it has not yet been widely exploited, but the risk remains high due to its remote nature and the fact that any user who can send requests to the macfilter interface can trigger a full compromise. Attackers would likely target the router from within the local network, where the macfilter API is exposed, and could achieve root access by crafting an injection payload.

Generated by OpenCVE AI on August 9, 2026 at 15:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the MSI Radix AXE6600 firmware to the latest version that removes the command injection flaw.
  • If an updated firmware release is unavailable, disable the macfilter feature or block access to the macfilter API through the router’s web interface or firewall settings.
  • Apply network segmentation and firewall rules to restrict external or untrusted hosts from contacting the router’s administration and macfilter endpoints.
  • Monitor router logs for suspicious command injection attempts and ensure that access to management interfaces requires strong authentication.

Generated by OpenCVE AI on August 9, 2026 at 15:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Msi
Msi radix Axe6600
Vendors & Products Msi
Msi radix Axe6600

Sun, 09 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Description MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system.
Title MSI Radix AXE6600 v781521 Command Injection via macfilter
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Msi Radix Axe6600
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-10T13:42:25.520Z

Reserved: 2026-08-08T23:03:19.076Z

Link: CVE-2026-71992

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-09T00:16:48.410

Modified: 2026-08-10T14:17:27.167

Link: CVE-2026-71992

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:27:56Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')