Description
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the dmz function to execute malicious commands and obtain root privileges on the underlying system.
Published: 2026-08-08
Score: 9.3 Critical
EPSS: 1.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker can exploit a command injection flaw in the dmz function of MSI Radix AXE6600 routers running firmware v781521. The flaw allows remote execution of arbitrary system commands, giving the attacker root privileges on the underlying device. By injecting commands into the dmz input field, the attacker can alter the router’s operating system, compromise network traffic, or launch further attacks. The weakness is identified as CWE-78, indicative of unsafe native command execution with insufficient input validation.

Affected Systems

The vulnerability affects MSI Radix AXE6600 Wi‑Fi 6E Tri‑Band Gaming Routers with firmware version v781521. No other products or versions are listed as vulnerable.

Risk and Exploitability

The CVSS score of 9.3 classifies this flaw as Critical, with a high likelihood of exploitation from the Internet where the router exposes the dmz function to remote users. The EPSS score of 1% indicates a low probability of exploitation, but not zero, and the vulnerability is not yet listed in the CISA KEV catalog, implying no known active exploit but a realistic threat if the router is reachable. Attackers would need remote network access to the device’s management interface to exploit the flaw; once successful, they gain full root control, threatening confidentiality, integrity, and availability of the network and connected devices.

Generated by OpenCVE AI on August 9, 2026 at 14:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router to the latest firmware supplied by MSI that resolves the command‑injection flaw
  • If a firmware update is unavailable, disable the dmz feature in the router’s administration interface or block the dmz port via the router’s firewall
  • After disabling dmz, verify that the input field no longer accepts injected commands by attempting benign test payloads and confirming no command execution occurs

Generated by OpenCVE AI on August 9, 2026 at 14:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Msi
Msi radix Axe6600
Vendors & Products Msi
Msi radix Axe6600

Sat, 08 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Description MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the dmz function to execute malicious commands and obtain root privileges on the underlying system.
Title MSI Radix AXE6600 v781521 Command Injection via dmz Function
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Msi Radix Axe6600
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-17T18:18:08.511Z

Reserved: 2026-08-08T23:03:19.076Z

Link: CVE-2026-71986

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-09T00:16:47.500

Modified: 2026-08-17T19:16:38.483

Link: CVE-2026-71986

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:28:13Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')