Description
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the accesscontrol function to execute malicious commands and obtain root privileges on the underlying system.
Published: 2026-08-08
Score: 9.3 Critical
EPSS: 1.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The MSI Radix AXE6600 router firmware version v781521 contains a command injection flaw in its accesscontrol function, identified as a CWE-78 weakness. This flaw allows an attacker to inject arbitrary system commands through the function, resulting in execution with root privileges on the device’s operating system.

Affected Systems

The affected product is MSI Radix AXE6600 network appliance, specifically firmware release v781521. No other versions are listed as impacted, and no additional products or variants are mentioned in the vendor data.

Risk and Exploitability

The CVSS base score of 9.3 reflects a critical level of severity, and the vulnerability can be triggered remotely via the accesscontrol function. The EPSS score of 1% indicates a very low but non‑zero probability of exploitation, although the exact likelihood remains uncertain. The router is not listed in the CISA KEV catalog, but the high severity warrants immediate attention.

Generated by OpenCVE AI on August 9, 2026 at 14:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device to the latest firmware version released by MSI that resolves the command injection issue.
  • If an upgrade cannot be applied promptly, disable or restrict the accesscontrol interface via the router’s web console to block unauthorized command execution.
  • Continuously monitor system logs for anomalous command activity and enforce firewall rules that limit remote access to the router’s management interfaces.

Generated by OpenCVE AI on August 9, 2026 at 14:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Msi
Msi radix Axe6600
Vendors & Products Msi
Msi radix Axe6600

Sat, 08 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Description MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the accesscontrol function to execute malicious commands and obtain root privileges on the underlying system.
Title MSI Radix AXE6600 v781521 Command Injection via accesscontrol Function
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Msi Radix Axe6600
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-11T17:52:20.725Z

Reserved: 2026-08-08T23:03:19.076Z

Link: CVE-2026-71985

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-09T00:16:47.360

Modified: 2026-08-11T18:18:23.027

Link: CVE-2026-71985

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:28:15Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')