A command injection flaw in the MSI Radix AXE6600 gaming router's OpenVPN function lets unauthenticated remote attackers run arbitrary commands as root, scoring a CVSS 9.8.
What Is It
CVE-2026-71993 is an OS command injection vulnerability (CWE-78) in MSI Radix AXE6600 router firmware version v781521. The flaw sits in the router's openvpn function, which fails to properly sanitize input before passing it to the underlying system shell. Per the advisory, attackers can inject malicious commands through that function and obtain root privileges on the device.
The vulnerability was disclosed via VulnCheck ([email protected]) and is currently in "Received" status in NVD, meaning it has been submitted but not yet fully analyzed or enriched by NVD staff.
Why It Matters
The CVSS v3.1 base score is 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. A CVSS v4.0 score of 9.3 (CRITICAL) was also assigned.
Every exploitability factor is worst-case: network attack vector, low attack complexity, no privileges required, and no user interaction. Impact is high across confidentiality, integrity, and availability. Successful exploitation yields root on the router; the device that sits between everything on the network and the internet. That means traffic interception, DNS manipulation, persistence, and lateral movement into anything behind it.
This CVE does not appear in the CISA Known Exploited Vulnerabilities catalog based on the supplied data, and no exploit maturity was defined in the CVSS v4.0 metrics. Absence from KEV is not evidence of safety here; consumer routers with pre-auth root RCE are historically prime botnet recruitment targets.
What's Vulnerable
- Vendor: MSI
- Product: Radix AXE6600 (WiFi 6E Tri-Band Gaming Router)
- Affected versions: firmware v781521, the only version listed in the NVD record (default status: affected)
No CPE configurations were published in the NVD record at time of writing.
Patch Status
No fixed version, patch, or vendor advisory is identified in the supplied source material, and no CISA-mandated remediation action applies since the CVE is not KEV-listed. The only vendor-side references provided are the MSI product support page and MSI's main site. Defenders should monitor the MSI Radix AXE6600 support page for firmware updates and, in the interim, restrict remote administrative access to the device.
Sources
- NVD, CVE-2026-71993: https://nvd.nist.gov/vuln/detail/CVE-2026-71993
- VulnCheck Advisory; MSI Radix AXE6600 v781521 Command Injection via openvpn Function: https://www.vulncheck.com/advisories/msi-radix-axe6600-v781521-command-injection-via-openvpn-function
- MSI Radix AXE6600 Support Page: https://us.msi.com/Networking/RadiX-AXE6600-WiFi-6E-Tri-Band-Gaming-Router/support
- MSI: https://www.msi.com/