Description
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the urlfilter function to inject malicious commands and obtain root privileges on the underlying system.
Published: 2026-08-08
Score: 9.3 Critical
EPSS: 1.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function, allowing remote attackers to execute arbitrary commands on the device and obtain root privileges. This flaw, classified as CWE‑78, enables attackers to inject malicious code through the web interface and control the underlying operating system.

Affected Systems

The vulnerability affects MSI Radix AXE6600 Wi‑Fi routers running firmware v781521. Users of this specific firmware revision should identify if their device is running the affected version.

Risk and Exploitability

The CVSS score of 9.3 indicates critical severity, the EPSS score is 1%, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the router’s web management interface, inferred from the fact that attackers can exploit the urlfilter function to inject malicious commands. Attackers can remotely exploit the flaw, potentially compromising the device and all connected networks. Given the high impact and remote attack vector, the risk is significant.

Generated by OpenCVE AI on August 9, 2026 at 15:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to a version that includes the fix for the urlfilter command injection issue.
  • If a patch is not yet available, restrict access to the router’s web management interface by blocking the relevant ports or by configuring the router to allow management only from trusted IP addresses.
  • Change the default administrator credentials and enforce strong passwords to limit the ability of attackers who might acquire remote access.

Generated by OpenCVE AI on August 9, 2026 at 15:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Msi
Msi radix Axe6600
Vendors & Products Msi
Msi radix Axe6600

Mon, 10 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 08 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Description MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the urlfilter function to inject malicious commands and obtain root privileges on the underlying system.
Title MSI Radix AXE6600 v781521 Command Injection via urlfilter
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Msi Radix Axe6600
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-10T14:46:59.343Z

Reserved: 2026-08-08T23:03:19.076Z

Link: CVE-2026-71984

cve-icon Vulnrichment

Updated: 2026-08-10T14:46:40.975Z

cve-icon NVD

Status : Received

Published: 2026-08-09T00:16:47.207

Modified: 2026-08-10T15:17:44.267

Link: CVE-2026-71984

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:28:17Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')