CVE-2026-71987

9.8

MSI · Radix AXE6600

The MSI Radix AXE6600 router firmware contains a command injection vulnerability in the alg function, allowing unauthenticated remote attackers to execute arbitrary commands on the device.

Executive summary

A critical command injection vulnerability in the MSI Radix AXE6600 router permits unauthenticated remote attackers to achieve remote code execution and root-level access.

Vulnerability

This is an OS command injection vulnerability (CWE-78) located in the alg function. Attackers can reach this function without authentication, enabling them to execute malicious commands directly on the router's operating system.

Business impact

The compromise of a router's core functionality, such as the application layer gateway (alg) service, can lead to complete network interception and the bypass of security policies. With a CVSS score of 9.8, this vulnerability is critical and poses a significant risk to the integrity of the entire network infrastructure connected to the affected device.

Remediation

Immediate Action: Update the MSI Radix AXE6600 firmware to the latest available version as provided by the manufacturer.

Proactive Monitoring: Monitor for unusual traffic patterns related to application layer gateway services and inspect system logs for anomalous command execution entries.

Compensating Controls: Implement network segmentation to ensure that even if the router is compromised, the impact on critical internal segments is minimized.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability represents a significant security gap that requires urgent remediation. Users should ensure their devices are running the latest firmware to prevent potential exploitation of the alg function.

More MSI CVEs

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section
  3. Fix documented per CVE record