SYS::ONLINE
Wasteland.
Briefs1798
Issues22
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-71993 2026-08-08

MSI Radix AXE6600 Router Hit by Critical Root-Level Command Injection (CVE-2026-71993)

"A command injection flaw in the MSI Radix AXE6600 gaming router's OpenVPN function lets unauthenticated remote attackers run arbitrary commands as root, scoring a CVSS 9.8."

A command injection flaw in the MSI Radix AXE6600 gaming router's OpenVPN function lets unauthenticated remote attackers run arbitrary commands as root, scoring a CVSS 9.8.

What Is It

CVE-2026-71993 is an OS command injection vulnerability (CWE-78) in MSI Radix AXE6600 router firmware version v781521. The flaw sits in the router's openvpn function, which fails to properly sanitize input before passing it to the underlying system shell. Per the advisory, attackers can inject malicious commands through that function and obtain root privileges on the device.

The vulnerability was disclosed via VulnCheck ([email protected]) and is currently in "Received" status in NVD, meaning it has been submitted but not yet fully analyzed or enriched by NVD staff.

Why It Matters

The CVSS v3.1 base score is 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. A CVSS v4.0 score of 9.3 (CRITICAL) was also assigned.

Every exploitability factor is worst-case: network attack vector, low attack complexity, no privileges required, and no user interaction. Impact is high across confidentiality, integrity, and availability. Successful exploitation yields root on the router; the device that sits between everything on the network and the internet. That means traffic interception, DNS manipulation, persistence, and lateral movement into anything behind it.

This CVE does not appear in the CISA Known Exploited Vulnerabilities catalog based on the supplied data, and no exploit maturity was defined in the CVSS v4.0 metrics. Absence from KEV is not evidence of safety here; consumer routers with pre-auth root RCE are historically prime botnet recruitment targets.

What's Vulnerable

No CPE configurations were published in the NVD record at time of writing.

Patch Status

No fixed version, patch, or vendor advisory is identified in the supplied source material, and no CISA-mandated remediation action applies since the CVE is not KEV-listed. The only vendor-side references provided are the MSI product support page and MSI's main site. Defenders should monitor the MSI Radix AXE6600 support page for firmware updates and, in the interim, restrict remote administrative access to the device.

Sources