What is CVE-2026-71993?
This vulnerability is a command injection flaw in the MSI Radix AXE6600 router firmware version v781521, specifically within the 'openvpn' function. Remote attackers can exploit the 'macfilter' function to inject malicious commands and achieve arbitrary code execution with root privileges on the affected device. Immediate firmware update is strongly recommended to mitigate this issue.
Azərbaycanca: Bu zəiflik MSI Radix AXE6600 router-in v781521 firmware versiyasında, xüsusilə 'openvpn' funksiyasında command injection boşluğudur. Uzaqdan hücum edən şəxslər 'macfilter' funksiyası vasitəsilə zərərli əmrlər yeridərək cihazda root hüquqları ilə ixtiyari kod icra edə bilərlər. Bu problemi aradan qaldırmaq üçün dərhal firmware yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: MSI
FAQ2
Which function do attackers exploit to leverage the CVE-2026-71993 vulnerability in the MSI Radix AXE6600 router?
Attackers exploit the 'macfilter' function to inject malicious commands and leverage this command injection flaw.
What level of privilege can an attacker gain on the device by successfully exploiting CVE-2026-71993?
By successfully exploiting this vulnerability, an attacker can achieve arbitrary code execution with root privileges on the device.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.