Summary
CVE-2026-71992 is an unauthenticated OS command injection vulnerability (CWE-78) in the MSI Radix AXE6600 router. The flaw resides in the device’s macfilter function and allows a remote attacker to execute arbitrary operating system commands with root privileges. It is rated Critical (CVSS v4.0 9.3 / CVSS v3.1 9.8).
Technical details
- Root cause: The
macfilterfunction fails to properly neutralize special elements in user-supplied input before passing it to a system command (CWE-78), allowing shell metacharacters to chain arbitrary commands. - Trigger conditions: Exploitation requires no authentication and no user interaction; a crafted request to the vulnerable
macfilterfunction is sufficient. - Attack vector: Network (remote), low attack complexity.
- Impact: Full compromise of the device — arbitrary command execution with root-level privileges, with high impact to confidentiality, integrity, and availability.
Affected software
- MSI Radix AXE6600 router firmware version v781521 and all earlier versions.
Severity
- CVSS v3.1 base score: 9.8 (Critical) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v4.0 base score: 9.3 (Critical) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Mitigation and recommended actions
- Immediate: Update the MSI Radix AXE6600 to firmware version v782418 or later, available from the MSI support portal.
- If no patch can be applied: Restrict access to the router’s management interface to trusted networks and users, and ensure the device is not exposed directly to the internet.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
MSI Router - Raw response body:
GRAXE66,RadiX AXE6600

