Description
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.
Published: 2026-08-08
Score: 9.3 Critical
EPSS: 1.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the firmware of MSI Radix AXE6600 routers and allows a remote attacker to inject arbitrary operating‑system commands via the alg function, leading to execution of commands with root privileges. This command‑injection weakness is identified as CWE‑78.

Affected Systems

MSI Radix AXE6600 routers running firmware version v781521 are affected. No other affected products or versions are listed.

Risk and Exploitability

The CVSS score of 9.3 classifies this flaw as critical. The EPSS score of 1% indicates a low but nonzero exploitation probability, and the vulnerability is not listed in CISA KEV. The description explicitly states that remote attackers can exploit the alg function to execute arbitrary commands. If successful, an attacker gains full control over the device.

Generated by OpenCVE AI on August 9, 2026 at 14:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Permanently install the latest MSI Radix AXE6600 firmware that includes the fix for the command‑injection flaw.
  • If a new firmware is not yet available, disable or block the alg function through the router’s configuration interface to prevent exposure to external traffic.
  • Restrict access to the router’s management interface to trusted IP addresses, a dedicated VLAN, or enforce firewall rules, and monitor logs for unauthorized command execution attempts.

Generated by OpenCVE AI on August 9, 2026 at 14:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Msi
Msi radix Axe6600
Vendors & Products Msi
Msi radix Axe6600

Sat, 08 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Description MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.
Title MSI Radix AXE6600 v781521 Command Injection via alg function
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Msi Radix Axe6600
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-10T13:42:00.995Z

Reserved: 2026-08-08T23:03:19.076Z

Link: CVE-2026-71987

cve-icon Vulnrichment

Updated: 2026-08-10T13:41:55.367Z

cve-icon NVD

Status : Received

Published: 2026-08-09T00:16:47.637

Modified: 2026-08-10T14:17:27.033

Link: CVE-2026-71987

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:28:11Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')