Summary
CVE-2026-71993 is an OS command injection (CWE-78) vulnerability in the MSI Radix AXE6600 Wi-Fi 6E gaming router. The openvpn function in firmware version v781521 fails to neutralize special elements in user-supplied input, allowing a remote, unauthenticated attacker to execute arbitrary commands on the device. It is rated Critical.
Technical details
- Root cause: Improper neutralization of special elements in input processed by the router’s
openvpnfunction, which is passed to an OS command without adequate sanitization or validation. - Trigger conditions: An attacker sends crafted input to the affected
openvpnfunction; no authentication or user interaction is required. - Attack vector: Network (AV:N), low complexity, no privileges required.
- Impact: Arbitrary command execution on the underlying operating system, leading to full compromise of confidentiality, integrity, and availability of the device.
Affected software
- MSI Radix AXE6600 router firmware version v781521 and earlier (all versions up to and including v781521).
Severity
- CVSS v3.1: 9.8 (Critical) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v4.0: 9.3 (Critical) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Mitigation and recommended actions
- Immediate: Apply the latest firmware for the Radix AXE6600 from MSI’s official product support downloads page as soon as a fixed release is available.
- If no patch: Do not expose the router’s management interface to the internet; restrict access to trusted management networks, disable remote administration, and segment the device from untrusted networks to limit reachability of the affected function.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
MSI Router - Raw response body:
GRAXE66,RadiX AXE6600

