CVE-2026-71984
MSI · Radix AXE6600
MSI Radix AXE6600 firmware v781521 contains a command injection vulnerability in the urlfilter function, allowing unauthenticated remote attackers to execute arbitrary commands as root.
Executive summary
A critical command injection vulnerability in the MSI Radix AXE6600 router allows unauthenticated remote attackers to achieve full system compromise.
Vulnerability
This is an OS command injection flaw (CWE-78) located within the urlfilter function. An unauthenticated attacker can inject and execute arbitrary commands on the underlying system with root privileges.
Business impact
The CVSS score of 9.8 highlights the critical risk posed by this vulnerability. Successful exploitation permits an attacker to take full control of the router, potentially leading to unauthorized access to the local area network, interception of sensitive data, and persistent threats within the enterprise environment.
Remediation
Immediate Action: Identify all MSI Radix AXE6600 devices and update them to the latest firmware version provided by MSI.
Proactive Monitoring: Monitor device logs for errors or entries related to the urlfilter function and inspect network traffic for signs of unauthorized management access.
Compensating Controls: Utilize a Web Application Firewall or similar filtering mechanism to inspect incoming traffic for malicious payloads, and restrict access to the router's web interface to trusted administrative IPs.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical severity of this command injection vulnerability, it is imperative to update the affected firmware immediately. Failure to address this flaw leaves the network perimeter exposed to full compromise by remote, unauthenticated actors.