,

Vulnerability Watch No34

📂 lollms Path Traversal Exposes Arbitrary Server Files
Anyone running lollms 2.1.0 should upgrade to version 3 promptly, especially where the service is reachable by untrusted users. The flaw enables unauthenticated file disclosure and could expose credentials or other sensitive server data.
CVE-2026-10595 is a path traversal vulnerability in parisneo/lollms version 2.1.0 affecting the SPA catch-all route in backend/routers/ui.py. URL-encoded dot-dot sequences can bypass path normalization, allowing an unauthenticated attacker to read arbitrary files from the server. The issue is rated HIGH with CVSS 7.5 and is resolved in version 3.
🔗 Read more 🔗
Source: NVD

🚨 MSI Radix AXE6600 OpenVPN Flaw Enables Root Command Execution
Organizations and users operating MSI Radix AXE6600 routers on firmware v781521 should treat this as an urgent patch or mitigation priority. Remote command execution as root can lead to complete device compromise.
CVE-2026-71993 is a command injection vulnerability in MSI Radix AXE6600 router firmware version v781521, associated with the openvpn function. Remote attackers can inject malicious commands and obtain root privileges on the affected device. The vulnerability is rated CRITICAL with CVSS 9.8.
🔗 Read more 🔗
Source: NVD

🚨 MSI Radix AXE6600 Mac Filter Bug Allows Root Commands
Patch or otherwise restrict access to affected MSI Radix AXE6600 routers as a top priority. Successful exploitation gives an attacker root-level command execution and effectively full control of the router.
CVE-2026-71992 is a command injection vulnerability in the macfilter function of MSI Radix AXE6600 router firmware version v781521. A remote attacker can inject arbitrary commands through the vulnerable function and gain root privileges on the underlying system. The issue is rated CRITICAL with CVSS 9.8.
🔗 Read more 🔗
Source: NVD

🚨 MSI Router Telnet Configuration Flaw Leads to Root Access
Administrators running the affected firmware should patch urgently and restrict management interfaces from untrusted networks until remediation is available. Root-level remote command execution makes this a full-device compromise risk.
CVE-2026-71991 is a command injection vulnerability in the TelnetSSH function used for Telnet configuration on MSI Radix AXE6600 firmware version v781521. Remote attackers can inject malicious commands through the Telnet configuration interface and obtain root privileges. The vulnerability is rated CRITICAL with CVSS 9.8.
🔗 Read more 🔗
Source: NVD

🚨 MSI Router SSH Configuration Flaw Enables Root Command Injection
Affected MSI Radix AXE6600 deployments should be patched or isolated urgently, with administrative access limited to trusted networks in the meantime. Exploitation can provide remote attackers with root control of the router.
CVE-2026-71990 is a command injection vulnerability in the TelnetSSH function used for SSH configuration on MSI Radix AXE6600 firmware version v781521. Remote attackers can inject malicious commands through the SSH configuration interface and obtain root privileges on the device. The vulnerability is rated CRITICAL with CVSS 9.8.
🔗 Read more 🔗
Source: NVD

🚨 MSI Radix URL Filter Flaw Gives Attackers Root Execution
Owners of affected MSI Radix AXE6600 routers should prioritize patching or vendor mitigations immediately. The ability to execute commands remotely as root means exploitation can result in complete router takeover.
CVE-2026-71984 is a command injection vulnerability in the urlfilter function of MSI Radix AXE6600 router firmware version v781521. Remote attackers can inject arbitrary malicious commands through the vulnerable function and obtain root privileges. The issue is rated CRITICAL with CVSS 9.8.
🔗 Read more 🔗
Source: NVD

🚨 MSI Radix Access Control Function Exposes Root Command Execution
Affected router deployments should be patched with high urgency or have access to vulnerable management functionality tightly restricted. Root-level command execution gives an attacker broad control over the device and network traffic.
CVE-2026-71985 is a command injection vulnerability in the accesscontrol function of MSI Radix AXE6600 router firmware version v781521. Remote attackers can execute malicious commands through the affected function and obtain root privileges on the underlying system. The vulnerability is rated CRITICAL with CVSS 9.8.
🔗 Read more 🔗
Source: NVD

🚨 MSI Radix DMZ Function Vulnerable to Root Command Injection
Administrators with MSI Radix AXE6600 routers on the affected firmware should remediate urgently and minimize exposure of management functions. Successful exploitation can hand an attacker complete root-level control.
CVE-2026-71986 is a command injection vulnerability in the dmz function of MSI Radix AXE6600 router firmware version v781521. A remote attacker can inject malicious commands through the function and gain root privileges on the affected device. The flaw is rated CRITICAL with CVSS 9.8.
🔗 Read more 🔗
Source: NVD

🚨 MSI Radix ALG Function Allows Remote Root Commands
Patch affected MSI Radix AXE6600 routers as soon as possible and restrict administrative exposure until fixed. A remote attacker who reaches the vulnerable function can potentially take full control of the device as root.
CVE-2026-71987 is a command injection vulnerability in the alg function of MSI Radix AXE6600 router firmware version v781521. Remote attackers can inject malicious commands through the vulnerable function and obtain root privileges on the device. The issue is rated CRITICAL with CVSS 9.8.
🔗 Read more 🔗
Source: NVD

🚨 MSI Radix Port Forwarding Flaw Enables Root Command Execution
Treat affected MSI Radix AXE6600 routers as an urgent remediation priority because the reported impact is remote root command execution. Administrators should also note the apparent function-name inconsistency in the source description when validating exposure.
CVE-2026-71988 is a command injection vulnerability in the portFw function of MSI Radix AXE6600 router firmware version v781521. The entry states that attackers can execute malicious commands and obtain root privileges, although its exploit description references the alg function. The vulnerability is rated CRITICAL with CVSS 9.8.
🔗 Read more 🔗
Source: NVD

🚨 MSI Radix Port Triggering Bug Can Lead to Root Compromise
Organizations using the affected MSI router firmware should patch or isolate these devices urgently because the stated impact is remote root-level execution. The source contains a function-name inconsistency, so defenders should account for that when checking affected interfaces.
CVE-2026-71989 is a command injection vulnerability in the porTrigger function of MSI Radix AXE6600 router firmware version v781521. The entry reports that attackers can execute malicious commands and obtain root privileges, although the exploitation sentence references the alg function. The issue is rated CRITICAL with CVSS 9.8.
🔗 Read more 🔗
Source: NVD

🚨 D-Link DWR-M961 Command Injection Grants Remote Root Access
Anyone operating the affected D-Link DWR-M961 hardware and software combination should prioritize patching or vendor-provided mitigation immediately. Remote root command execution creates a severe risk of complete router compromise.
CVE-2026-71956 is a command injection vulnerability affecting D-Link DWR-M961 hardware version C1 running software version 1.1.2_C1_202602110044. A remote attacker can inject arbitrary commands into the netDig.ping.dst field of the app.cgi interface and execute them with root privileges. The vulnerability is rated CRITICAL with CVSS 9.8.
🔗 Read more 🔗
Source: NVD