Description
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.
Published: 2026-08-08
Score: 9.3 Critical
EPSS: 2.5% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A command injection vulnerability exists in the porTrigger function of the MSI Radix AXE6600 router firmware v781521 (CWE-78). Attackers can supply crafted input to this function, which is processed by the underlying alg function, allowing arbitrary operating system commands to be executed with root privileges on the device. This flaw enables a remote attacker to run any command on the router’s host system.

Affected Systems

The affected system is the MSI Radix AXE6600 router running firmware version v781521. No other MSI products or firmware releases are listed as vulnerable in the advisory.

Risk and Exploitability

The CVSS score of 9.3 indicates high severity, and the EPSS score of 2 % reflects a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it remotely through the alg function, which is reachable over the network, making arbitrary command execution possible without local access. The impact is therefore significant due to the remote attack vector and root‑level execution.

Generated by OpenCVE AI on September 25, 2026 at 01:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the router firmware to the latest MSI Radix AXE6600 release that addresses the command injection issue
  • If a patch is not yet available, block or disable external access to the porTrigger/alg function or the ports it uses through the router’s firewall settings
  • Apply additional hardening: enforce strong administrative passwords, restrict remote management access, and monitor for anomalous command execution logs

Generated by OpenCVE AI on September 25, 2026 at 01:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Msi
Msi radix Axe6600
Vendors & Products Msi
Msi radix Axe6600

Mon, 10 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 08 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Description MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.
Title MSI Radix AXE6600 v781521 Command Injection via porTrigger function
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Msi Radix Axe6600
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:18:46.122Z

Reserved: 2026-08-08T23:03:19.076Z

Link: CVE-2026-71989

cve-icon Vulnrichment

Updated: 2026-08-10T14:49:26.185Z

cve-icon NVD

Status : Deferred

Published: 2026-08-09T00:16:47.953

Modified: 2026-08-31T20:30:14.457

Link: CVE-2026-71989

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T01:30:20Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')