Description
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through the pin2g, pin5g, or pin6g parameters. Attackers can exploit these unsanitized parameters to execute arbitrary commands on the affected device and obtain root privileges.
Published: 2026-08-08
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the wps.cgi interface of MSI Radix AXE6600 firmware v781521 permits attackers to inject arbitrary commands through unsanitized parameters pin2g, pin5g, or pin6g. This is a classic instance of command injection (CWE-78), allowing execution of any shell command with full root privileges on the device. The scope of impact is system-wide, compromising confidentiality, integrity, and availability of the router and any networks connected to it.

Affected Systems

The affected product is the MSI Radix AXE6600 Wi‑Fi 6E gaming router running firmware version v781521. No other vendors or product lines are listed as affected.

Risk and Exploitability

The CVSS score of 9.3 indicates a critical severity. The EPSS score is not provided, so the current exploitation probability is unknown, but the lack of a KEV listing does not rule out active attacks. The likely attack vector is remote over the network via HTTP requests to wps.cgi, and the vulnerability can be triggered without authentication if WPS is enabled and accessible.

Generated by OpenCVE AI on August 9, 2026 at 00:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from MSI that addresses the command injection flaw.
  • Disable Wi‑Fi Protected Setup (WPS) on the router to eliminate the vulnerable interface.
  • Restrict management access to the router by configuring the firewall to allow local‑network only or by disabling the web interface entirely.

Generated by OpenCVE AI on August 9, 2026 at 00:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 08 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Description MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through the pin2g, pin5g, or pin6g parameters. Attackers can exploit these unsanitized parameters to execute arbitrary commands on the affected device and obtain root privileges.
Title MSI Radix AXE6600 v781521 Command Injection via wps.cgi
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-08T23:10:31.573Z

Reserved: 2026-08-08T23:03:19.076Z

Link: CVE-2026-71983

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-09T00:30:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')