CVE-2026-71988

MSI · Radix AXE6600

MSI Radix AXE6600 firmware v781521 contains a command injection vulnerability in the portFw function, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges.

Executive summary

A critical command injection vulnerability in the MSI Radix AXE6600 router allows unauthenticated remote attackers to achieve full system compromise.

Vulnerability

This is an OS command injection flaw (CWE-78) located within the portFw function. An unauthenticated attacker can leverage the alg function to inject and execute malicious commands on the underlying operating system.

Business impact

The vulnerability carries a CVSS score of 9.8, indicating a critical severity level. Successful exploitation grants the attacker root-level access to the router, which could lead to complete network interception, unauthorized data exfiltration, or the inclusion of the device in a botnet. Such a compromise poses a severe risk to organizational confidentiality and network integrity.

Remediation

Immediate Action: Identify all deployed MSI Radix AXE6600 devices and update the firmware to the latest available version provided by the manufacturer.

Proactive Monitoring: Monitor network traffic for unusual outbound connections from the router and review device system logs for unexpected process execution or configuration changes.

Compensating Controls: If an update cannot be applied immediately, restrict administrative access to the router to trusted internal IP addresses only and disable unnecessary features like port forwarding if they are not required for business operations.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical nature of this vulnerability and the potential for total device takeover, immediate patching is required. Administrators should verify the firmware status of all affected routers and prioritize the application of vendor-provided updates to mitigate the risk of remote code execution.