Description
MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.
Published: 2026-08-08
Score: 9.3 Critical
EPSS: 1.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A command injection flaw exists in the porTrigger function of MSI Radix AXE6600 router firmware v781521. By sending specially crafted input to this function, an attacker can inject operating system commands, which are executed with root privileges on the device. This permits full compromise of the device, enabling data exfiltration, persistence, or further network attacks.

Affected Systems

MSI Radix AXE6600 routers running firmware version v781521 are affected. No other MSI products or firmware versions are listed as vulnerable.

Risk and Exploitability

The CVSS score of 9.3 indicates high severity, and the EPSS score of 1% indicates a low but non-zero probability of exploitation. The vulnerability is not listed in CISA KEV. Attackers can exploit it remotely through the alg function, which is reachable over the network, thereby facilitating arbitrary command execution without local access. Given the remote attack vector and the ability to gain root, the risk is substantial.

Generated by OpenCVE AI on August 9, 2026 at 14:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the router firmware to the latest MSI Radix AXE6600 release that addresses the command injection issue
  • If a patch is not yet available, block or disable external access to the porTrigger/alg function or the ports it uses through the router’s firewall settings
  • Apply additional hardening: enforce strong administrative passwords, restrict remote management access, and monitor for anomalous command execution logs

Generated by OpenCVE AI on August 9, 2026 at 14:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Msi
Msi radix Axe6600
Vendors & Products Msi
Msi radix Axe6600

Mon, 10 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 08 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Description MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.
Title MSI Radix AXE6600 v781521 Command Injection via porTrigger function
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Msi Radix Axe6600
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-10T14:49:47.800Z

Reserved: 2026-08-08T23:03:19.076Z

Link: CVE-2026-71989

cve-icon Vulnrichment

Updated: 2026-08-10T14:49:26.185Z

cve-icon NVD

Status : Received

Published: 2026-08-09T00:16:47.953

Modified: 2026-08-10T15:17:44.397

Link: CVE-2026-71989

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:28:05Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')