CVE-2026-71985
MSI · Radix AXE6600
A command injection vulnerability in the MSI Radix AXE6600 router firmware allows unauthenticated remote attackers to execute arbitrary commands with root privileges via the accesscontrol function.
Executive summary
A critical command injection vulnerability in the MSI Radix AXE6600 router allows unauthenticated remote attackers to gain full system control.
Vulnerability
This is an OS command injection flaw (CWE-78) located in the accesscontrol function. The vulnerability is exploitable by unauthenticated remote attackers who can pass malicious input to the device, resulting in command execution at the root privilege level.
Business impact
With a CVSS score of 9.8, this vulnerability represents a critical risk to organizational security. A successful exploit grants an attacker full root access to the router, which can be leveraged to intercept network traffic, pivot into internal segments, or deploy persistent backdoors, leading to severe data compromise and total loss of network integrity.
Remediation
Immediate Action: Update the firmware of all affected MSI Radix AXE6600 devices to the latest available version provided by the manufacturer.
Proactive Monitoring: Monitor network traffic for unusual outbound connections or spikes in administrative interface access attempts.
Compensating Controls: Restrict access to the router management interface to trusted internal IP addresses only, and employ a firewall to block unauthorized external access to the device.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this vulnerability necessitates immediate attention. Organizations utilizing the MSI Radix AXE6600 must prioritize firmware updates to close this critical command injection vector and prevent unauthorized root-level system access.