What you need to know today.
Critical command injection and buffer overflow flaws impact MSI and D-Link routers, alongside a vulnerability in Shenzhen Aitemi Wi-Fi Repeaters.

Multiple command injection vulnerabilities have been discovered in MSI Radix AXE6600 routers, firmware version v781521. These flaws affect various functions including openvpn, macfilter, TelnetSSH, porTrigger, portFw, alg, dmz, accesscontrol, and urlfilter. Remote attackers can exploit these vulnerabilities to execute arbitrary commands on affected devices. The specific CVEs are CVE-2026-71993, CVE-2026-71992, CVE-2026-71991, CVE-2026-71990, CVE-2026-71989, CVE-2026-71988, CVE-2026-71987, CVE-2026-71986, CVE-2026-71985, and CVE-2026-71984. Additionally, CVE-2026-71983 details a command injection vulnerability in the wps.cgi interface of the same router model, exploitable via specific parameters.
D-Link DWR-M961 routers, hardware version C1, are affected by several critical vulnerabilities. Versions prior to 1.1.5_C1_202607071108 contain command injection flaws in interfaces such as /boafrm/formWsc, /boafrm/formL2tpv3ConfigSetup, /boafrm/formNtp, /boafrm/formPinManageSetup, and /boafrm/formIMEISetup. These allow remote attackers to inject malicious commands. Furthermore, buffer overflow vulnerabilities exist in the quicksetup.cgi and app.cgi interfaces (CVE-2026-71958, CVE-2026-71957), which can be triggered by overly long strings. Another command injection vulnerability in app.cgi (CVE-2026-71956) allows arbitrary command injection through the netDig.ping.d parameter. The affected CVEs include CVE-2026-71958, CVE-2026-71957, CVE-2026-71956, CVE-2026-71955, CVE-2026-71954, CVE-2026-71953, CVE-2026-71952, and CVE-2026-71951.
A critical vulnerability (CVE-2026-19348) has been identified in Shenzhen Aitemi M300 Wi-Fi Repeaters, specifically impacting the sprintf function within the /protocol.csp file. This flaw allows for potential manipulation through crafted requests. The exact impact and exploitability details are still emerging, but it represents a significant security concern for users of this device.