CVE-2026-71988
MSI · Radix AXE6600
MSI Radix AXE6600 firmware v781521 contains a command injection vulnerability in the portFw function, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges.
Executive summary
A critical command injection vulnerability in the MSI Radix AXE6600 router allows unauthenticated remote attackers to achieve full system compromise.
Vulnerability
This is an OS command injection flaw (CWE-78) located within the portFw function. An unauthenticated attacker can leverage the alg function to inject and execute malicious commands on the underlying operating system.
Business impact
The vulnerability carries a CVSS score of 9.8, indicating a critical severity level. Successful exploitation grants the attacker root-level access to the router, which could lead to complete network interception, unauthorized data exfiltration, or the inclusion of the device in a botnet. Such a compromise poses a severe risk to organizational confidentiality and network integrity.
Remediation
Immediate Action: Identify all deployed MSI Radix AXE6600 devices and update the firmware to the latest available version provided by the manufacturer.
Proactive Monitoring: Monitor network traffic for unusual outbound connections from the router and review device system logs for unexpected process execution or configuration changes.
Compensating Controls: If an update cannot be applied immediately, restrict administrative access to the router to trusted internal IP addresses only and disable unnecessary features like port forwarding if they are not required for business operations.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical nature of this vulnerability and the potential for total device takeover, immediate patching is required. Administrators should verify the firmware status of all affected routers and prioritize the application of vendor-provided updates to mitigate the risk of remote code execution.