CVE-2026-71987

MSI · Radix AXE6600

The MSI Radix AXE6600 router firmware contains a command injection vulnerability in the alg function, allowing unauthenticated remote attackers to execute arbitrary commands on the device.

Executive summary

A critical command injection vulnerability in the MSI Radix AXE6600 router permits unauthenticated remote attackers to achieve remote code execution and root-level access.

Vulnerability

This is an OS command injection vulnerability (CWE-78) located in the alg function. Attackers can reach this function without authentication, enabling them to execute malicious commands directly on the router's operating system.

Business impact

The compromise of a router's core functionality, such as the application layer gateway (alg) service, can lead to complete network interception and the bypass of security policies. With a CVSS score of 9.8, this vulnerability is critical and poses a significant risk to the integrity of the entire network infrastructure connected to the affected device.

Remediation

Immediate Action: Update the MSI Radix AXE6600 firmware to the latest available version as provided by the manufacturer.

Proactive Monitoring: Monitor for unusual traffic patterns related to application layer gateway services and inspect system logs for anomalous command execution entries.

Compensating Controls: Implement network segmentation to ensure that even if the router is compromised, the impact on critical internal segments is minimized.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability represents a significant security gap that requires urgent remediation. Users should ensure their devices are running the latest firmware to prevent potential exploitation of the alg function.