CVE-2026-71983
MSI · Radix AXE6600
MSI Radix AXE6600 router firmware contains a command injection vulnerability in the wps.cgi interface, allowing unauthenticated remote attackers to execute commands via the pin parameters.
Executive summary
An unauthenticated remote command injection vulnerability in the MSI Radix AXE6600 router firmware enables attackers to achieve root-level code execution.
Vulnerability
This vulnerability involves improper neutralization of special elements in the wps.cgi interface (CWE-78). By submitting malicious input through the pin2g, pin5g, or pin6g parameters, an unauthenticated attacker can execute arbitrary OS commands with root privileges.
Business impact
The CVSS score of 9.8 reflects the extreme risk posed by this vulnerability. Successful exploitation permits full administrative control over the network gateway, enabling attackers to monitor traffic, exfiltrate sensitive data, or disrupt business operations entirely.
Remediation
Immediate Action: Apply the latest firmware update for the MSI Radix AXE6600 to remediate the command injection flaw in the WPS interface.
Proactive Monitoring: Review system logs for suspicious activity targeting the wps.cgi interface or unusual parameter strings.
Compensating Controls: Disable the WPS (Wi-Fi Protected Setup) feature if it is not strictly required for network operations, as this significantly reduces the attack surface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical nature of this vulnerability, administrators should treat this as a high-priority security event. Ensure all affected devices are updated immediately and consider disabling the vulnerable WPS functionality until the patch is successfully applied.