Description
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system.
Published: 2026-08-09
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

MSI Radix AXE6600 firmware version v781521 includes a command injection flaw in the openvpn function that lets attackers run arbitrary commands with root privileges on the device. The flaw enables complete compromise of the router, allowing an attacker to modify network traffic, install malicious software, or use the device as a pivot for further attacks in the local network.

Affected Systems

MSI Radix AXE6600 Wi‑Fi routers running firmware version v781521 are affected. No other firmware releases or vendor products are listed as vulnerable.

Risk and Exploitability

The CVSS score of 9.3 reflects the potential for full system compromise. EPSS information is not available, so the exact likelihood of exploitation remains unknown, but the high severity and lack of containment mechanisms make this vulnerability a serious threat. The flaw can be exploited remotely via the openvpn service, using the macfilter method to inject malicious code—an attack path that requires network access to the router’s administrative interface or VPN capability. The vulnerability is not listed in CISA’s KEV catalog, but its features make it an attractive target for attackers.

Generated by OpenCVE AI on August 9, 2026 at 01:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update released by MSI that addresses the command injection flaw in the openvpn function.
  • If the openvpn service is not required for your deployment, disable or remove the openvpn functionality to eliminate the attack surface.
  • Restrict administrative access to the router by limiting IP ranges that can reach the web interface, enable firewall rules to block unauthorized traffic, and monitor logs for suspicious activity indicative of injection attempts.

Generated by OpenCVE AI on August 9, 2026 at 01:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 09 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Description MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system.
Title MSI Radix AXE6600 v781521 Command Injection via openvpn function
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-09T00:00:05.679Z

Reserved: 2026-08-08T23:57:54.802Z

Link: CVE-2026-71993

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-09T01:30:17Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')