Description
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system.
Published: 2026-08-08
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The MSI Radix AXE6600 firmware version v781521 contains a command injection flaw in the macfilter function that allows a remote attacker to inject and execute arbitrary operating‑system commands on the device. The vulnerability escalates privileges to root, providing full control over the router’s underlying system and allowing the attacker to perform any action the device owner can, including modifying traffic, installing persistence mechanisms, or compromising connected devices.

Affected Systems

MSI Radix AXE6600 WiFi 6E Tri‑Band Gaming Router running firmware version v781521 is affected. No other firmware revisions are listed as vulnerable in the CNA data.

Risk and Exploitability

The CVSS score of 9.3 indicates the vulnerability is severe, with the potential for complete system takeover. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting it has not yet been widely exploited, but the risk remains high due to its remote nature and the fact that any user who can send requests to the macfilter interface can trigger a full compromise. Attackers would likely target the router from within the local network, where the macfilter API is exposed, and could achieve root access by crafting an injection payload.

Generated by OpenCVE AI on August 9, 2026 at 01:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the MSI Radix AXE6600 firmware to the latest version that removes the command injection flaw.
  • If an updated firmware release is unavailable, disable the macfilter feature or block access to the macfilter API through the router’s web interface or firewall settings.
  • Apply network segmentation and firewall rules to restrict external or untrusted hosts from contacting the router’s administration and macfilter endpoints.
  • Monitor router logs for suspicious command injection attempts and ensure that access to management interfaces requires strong authentication.

Generated by OpenCVE AI on August 9, 2026 at 01:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 09 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Description MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system.
Title MSI Radix AXE6600 v781521 Command Injection via macfilter
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-08T23:52:58.047Z

Reserved: 2026-08-08T23:03:19.076Z

Link: CVE-2026-71992

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-09T01:30:17Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')