VYPR
AI Brief2026-08-10· generated Aug 10, 2026

Critical Flaws Found in Routers and Libxml2

Critical command injection and memory corruption flaws disclosed in MSI routers, D-Link routers, and libxml2 pose significant risks.

Multiple command injection vulnerabilities have been disclosed in MSI Radix AXE6600 routers (firmware v781521), impacting functions such as openvpn, TelnetSSH, macfilter, portFw, dmz, and accesscontrol. These flaws allow remote attackers to execute arbitrary commands on affected devices by exploiting specific configuration interfaces. The vulnerabilities, including CVE-2026-71993, CVE-2026-71991, CVE-2026-71990, CVE-2026-71988, CVE-2026-71986, CVE-2026-71985, and CVE-2026-71983, carry a critical severity and a CVSS score of 9.8, indicating a high risk of exploitation. No specific patch information was provided, but users are advised to update their firmware.

D-Link DWR-M961 routers (hardware C1, specific software/firmware versions) are affected by a series of critical vulnerabilities, including command injection and buffer overflow flaws. These issues are present in various interfaces such as app.cgi, /boafrm/formWsc, /boafrm/formL2tpv3ConfigSetup, and others. Remote attackers can exploit these vulnerabilities to execute arbitrary commands or cause memory corruption. The affected CVEs include CVE-2026-71957, CVE-2026-71956, CVE-2026-71955, CVE-2026-71954, CVE-2026-71952, CVE-2026-71951, CVE-2026-71949, CVE-2026-71947, and CVE-2026-71944. As Vypr Intelligence reported, these vulnerabilities pose a significant risk to network security. Firmware updates are recommended.

Critical vulnerabilities have been identified in libxml2, a widely used XML parsing library. CVE-2025-49796, described as a memory corruption issue, can be triggered by processing specific sch:name elements in crafted XML files, potentially leading to crashes. Additionally, CVE-2025-49794 details a use-after-free vulnerability that occurs during XPath element parsing under certain schematron conditions. Both vulnerabilities, affecting Red Hat and Xmlsoft products, carry a high risk score. As noted in CISA ICS Advisories and CISA ICS Advisories, these flaws could allow attackers to achieve code execution or denial-of-service conditions. Mitigation strategies may involve input validation or updating to patched versions of libxml2.

A critical vulnerability (CVE-2026-19348) has been found in Shenzhen Aitemi M300 Wi-Fi Repeaters. The flaw resides in the sprintf function within the /protocol.csp file, specifically when handling net configurations. This vulnerability allows for remote attackers to potentially execute arbitrary code or commands by manipulating network settings. The high CVSS score of 9.8 underscores the severity of this issue, and users are advised to seek vendor guidance for remediation, as no specific patch details were immediately available.

Synthesized by Vypr AI
Critical Flaws Found in Routers and Libxml2 · VYPR