A command injection flaw in the MSI Radix AXE6600's macfilter function lets unauthenticated remote attackers execute arbitrary commands as root, rated CVSS 9.8 CRITICAL.
What Is It
CVE-2026-71992 is an OS command injection vulnerability (CWE-78) in MSI Radix AXE6600 router firmware. The macfilter function fails to properly neutralize special elements in input passed to an underlying system command. An attacker can inject malicious commands through this function and execute them on the device, obtaining root privileges on the underlying system.
The CVE record is newly published, with disclosure credited to VulnCheck. Its NVD status is currently "Received," meaning the record is still awaiting full analysis.
Why It Matters
The CVSS 3.1 base score is 9.8 (CRITICAL) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Under CVSS 4.0, the score is 9.3 (CRITICAL).
Every exploitability factor is at its worst case: the attack is reachable over the network, requires low complexity, needs no privileges, and requires no user interaction. Confidentiality, integrity, and availability impacts are all HIGH. Because successful exploitation grants root, an attacker gains full control of the router; a position that sits directly on the network perimeter and mediates all traffic behind it.
No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation at this time.
What's Vulnerable
- Vendor: MSI
- Product: Radix AXE6600 (WiFi 6E Tri-Band Gaming Router)
- Affected versions: all firmware versions up to and including v781521 (default status: affected)
No CPE entries have been assigned to this record yet.
Patch Status
The supplied source material does not identify a fixed firmware version, patch, or vendor advisory. No CISA KEV required action or remediation deadline was provided.
Administrators should monitor the MSI Radix AXE6600 support page (linked below) for firmware updates. Until a fix is confirmed, restricting network reachability of the router's management interface is the only mitigation supported by the available data.
Sources
- NVD, CVE-2026-71992: https://nvd.nist.gov/vuln/detail/CVE-2026-71992
- VulnCheck Advisory; MSI Radix AXE6600 v781521 Command Injection via macfilter: https://www.vulncheck.com/advisories/msi-radix-axe6600-v781521-command-injection-via-macfilter
- MSI Radix AXE6600 Support/Downloads: https://us.msi.com/Networking/RadiX-AXE6600-WiFi-6E-Tri-Band-Gaming-Router/support
- MSI: https://www.msi.com/