CVE-2026-71986
MSI · Radix AXE6600
The MSI Radix AXE6600 router firmware contains a command injection vulnerability in the dmz function, which allows unauthenticated remote attackers to execute arbitrary commands with root privileges.
Executive summary
A critical command injection vulnerability in the MSI Radix AXE6600 router enables unauthenticated remote attackers to execute arbitrary code and gain root access.
Vulnerability
This is an OS command injection vulnerability (CWE-78) occurring within the dmz function. The attack vector is network-based and requires no authentication, allowing an attacker to manipulate the underlying system shell remotely.
Business impact
Successful exploitation allows an attacker to gain full control over the router, potentially turning it into a pivot point for further lateral movement within the enterprise or home network. Given the CVSS score of 9.8, this vulnerability represents an imminent threat to network security and data privacy, as the device acts as a primary gateway for traffic.
Remediation
Immediate Action: Identify the current firmware version and update the MSI Radix AXE6600 to the latest vendor-supplied patch.
Proactive Monitoring: Review system logs for signs of unauthorized commands or unexpected configuration changes, specifically focusing on the DMZ settings page.
Compensating Controls: Restrict access to the router's management interface to trusted management IP addresses and employ firewall rules to block unsolicited incoming traffic.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this issue demands immediate attention. Administrators should verify the firmware version and apply the latest security updates provided by MSI to neutralize this command injection risk.