CVE-2026-71983

MSI · Radix AXE6600

MSI Radix AXE6600 router firmware contains a command injection vulnerability in the wps.cgi interface, allowing unauthenticated remote attackers to execute commands via the pin parameters.

Executive summary

An unauthenticated remote command injection vulnerability in the MSI Radix AXE6600 router firmware enables attackers to achieve root-level code execution.

Vulnerability

This vulnerability involves improper neutralization of special elements in the wps.cgi interface (CWE-78). By submitting malicious input through the pin2g, pin5g, or pin6g parameters, an unauthenticated attacker can execute arbitrary OS commands with root privileges.

Business impact

The CVSS score of 9.8 reflects the extreme risk posed by this vulnerability. Successful exploitation permits full administrative control over the network gateway, enabling attackers to monitor traffic, exfiltrate sensitive data, or disrupt business operations entirely.

Remediation

Immediate Action: Apply the latest firmware update for the MSI Radix AXE6600 to remediate the command injection flaw in the WPS interface.

Proactive Monitoring: Review system logs for suspicious activity targeting the wps.cgi interface or unusual parameter strings.

Compensating Controls: Disable the WPS (Wi-Fi Protected Setup) feature if it is not strictly required for network operations, as this significantly reduces the attack surface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical nature of this vulnerability, administrators should treat this as a high-priority security event. Ensure all affected devices are updated immediately and consider disabling the vulnerable WPS functionality until the patch is successfully applied.