External risk intelligence

MSI Radix AXE6600 Command Injection via macfilter

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-71992

The vulnerability exists in a home/small office router firmware. Routers are designed to be internet-facing by default, and management features like MAC filtering are often accessible via the device's web interface, making this a public-facing service in standard deployments.

OS Command Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A command injection vulnerability has been identified in the firmware of MSI Radix AXE6600 routers. This flaw could allow remote attackers to execute arbitrary commands and potentially gain root privileges on the affected devices. The main concern at this time is confirming relevance and exposure to our network infrastructure.

  • Unauthenticated commands can be run remotely.
  • Affects networking devices facing the internet.
  • Confirm relevance and exposure to our systems.

Attack Path

How an attacker could exploit the issue

An attacker could reach the vulnerable component by targeting the router's web interface, which is often exposed to the internet. By interacting with the MAC filter function, an attacker can inject commands, potentially gaining full control of the device.

  • No special access needed.
  • Triggered through MAC filter function.
  • Root access to the device.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated remote attacker to execute arbitrary commands on the affected router, potentially leading to a complete system compromise. The attacker could exploit the macfilter function when it is accessible externally.

  • Router system data.
  • Remote command injection.
  • Full device control.

Operational Fix

Recommended remediation, mitigation, and detection steps

The MSI Radix AXE6600 router firmware is susceptible to command injection, potentially granting attackers root access. Given this is a network device typically exposed to the internet, the initial priority is for the infrastructure or network security teams to identify all deployed instances of this firmware. Confirming reachability and business criticality will help prioritize remediation efforts, likely involving coordination with the vendor for a fix.

  • Infrastructure or Network Security teams own this.
  • Verify firmware reachability and criticality.
  • Plan vendor coordination for remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the MSI Radix AXE6600?

The MSI Radix AXE6600 is a high-performance WiFi 6E tri-band gaming router. It is designed to manage home or small office network traffic, providing wireless connectivity for devices while offering administrative features like MAC address filtering to control which hardware is allowed to join the network.

How does command injection work in CVE-2026-71992?

This vulnerability, classified as CWE-78 (OS Command Injection), occurs when the router fails to properly sanitize user input. By sending specifically crafted data to the MAC filter function, an attacker can trick the system into executing unauthorized operating system commands with root privileges, effectively taking control of the device.

Do I need to be logged into the router to trigger this bug?

No. The vulnerability allows for unauthenticated remote execution, meaning an attacker does not need prior login credentials or administrative access to the router to initiate the attack. However, the attack relies on interacting specifically with the MAC filter functionality via the device's web interface.

Is my device at risk based on Halo Surface Signal?

Halo Surface Signal identifies this as a high-risk issue because the device is a router, which is typically designed to be internet-facing. Because management features like the MAC filter are often accessible through the web interface, the vulnerability is likely reachable from the public internet in standard configurations.

When should I take action for this firmware vulnerability?

You should prioritize identifying all instances of the MSI Radix AXE6600 running the affected firmware version. Once identified, verify if the device's management interface is reachable from the internet. Coordinate with your network team or the vendor to monitor for authorized firmware updates to address this flaw.

References