Description
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.
Published: 2026-08-08
Score: 9.3 Critical
EPSS: 1.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a command injection flaw in the portFw function of MSI Radix AXE6600 firmware v781521. Remote attackers can inject arbitrary shell commands via the alg function, potentially leading to full control of the device and root access.

Affected Systems

Affected systems include MSI Radix AXE6600 routers running firmware version v781521. No other affected versions are publicly identified.

Risk and Exploitability

The CVSS score of 9.3 classifies the issue as critical, and an EPSS score of 1% indicates a low but non-zero exploitation probability. The vulnerability is exploitable remotely, likely through the router’s network interface, and could grant attackers root privileges on the underlying Linux system.

Generated by OpenCVE AI on August 9, 2026 at 14:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from MSI that addresses the command injection vulnerability.
  • Restrict external access to the router’s management interface, limiting it to trusted local networks or VPN only.
  • Change default administrator passwords and enable two‑factor authentication if supported.

Generated by OpenCVE AI on August 9, 2026 at 14:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Msi
Msi radix Axe6600
Vendors & Products Msi
Msi radix Axe6600

Tue, 11 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 08 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Description MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.
Title MSI Radix AXE6600 v781521 Command Injection via portFw function
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Msi Radix Axe6600
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-11T01:35:26.993Z

Reserved: 2026-08-08T23:03:19.076Z

Link: CVE-2026-71988

cve-icon Vulnrichment

Updated: 2026-08-11T01:35:23.001Z

cve-icon NVD

Status : Received

Published: 2026-08-09T00:16:47.780

Modified: 2026-08-11T03:18:01.300

Link: CVE-2026-71988

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:28:08Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')